MAL-2023-8370
Dashboard / Malicious Package / MAL-2023-8370
MAL-2023-8370
Published: 13 Oct 2023Last Modified: 13 Oct 2023
Summary: Malicious code in tencent-cloud-python-sdk (PyPI)
Details: Source: google-open-source-security (bf236cca18e4d157a57cd3de7abed8ad967103c42b9ae53f5026174af46b64a4) Attack targeted at users of Alibaba, AWS and Telegram via malicious packages published to PyPI. The malicious code was hidden in strategicly chosen functions and would only trigger when these functions were called. The malicious code does not automatically run on install or import, helping the packages evade detection.
References: https://blog.phylum.io/cloud-provider-credentials-targeted-in-new-pypi-malware-campaign/
Affected packages
Package
Name: tencent-cloud-python-sdk
Purl: pkg:pypi/tencent-cloud-python-sdk
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
