MAL-2023-8354
Dashboard / Malicious Package / MAL-2023-8354
MAL-2023-8354
Summary: Malicious code in alibabacloud-vpc20180317 (PyPI)
Details: Source: checkmarx (0c24b33d1db8fffd5daaf1985d25add4bc66e7879e1a6efbc7ae706816931834) Malicious Typosquatting packages campaign targeting developers, steals cloud service credentials Source: google-open-source-security (54cd0ad4627d65e2f30a3b3b165148a924014b94af0d3a6a0b23a265f2b02b4c) Attack targeted at users of Alibaba, AWS and Telegram via malicious packages published to PyPI. The malicious code was hidden in strategicly chosen functions and would only trigger when these functions were called. The malicious code does not automatically run on install or import, helping the packages evade detection.
References: https://checkmarx.com/blog/users-of-telegram-aws-and-alibaba-cloud-targeted-in-latest-supply-chain-attack/, https://medium.com/checkmarx-security/users-of-telegram-aws-and-alibaba-cloud-targeted-in-latest-supply-chain-attack-f44e60eacbdd
Affected packages
Package
Name: alibabacloud-vpc20180317
Purl: pkg:pypi/alibabacloud-vpc20180317
Affected ranges
Type: ECOSYSTEM
Events:
