MAL-2024-11622
Dashboard / Malicious Package / MAL-2024-11622
MAL-2024-11622
Summary: Malicious code in larpexodus (PyPI)
Details: Source: kam193 (5b391a50d47eceb41e0f102a5825b7e68d35a2c950ecc91f32c2b48e890792b9) Importing a module starts downloading and executing an infostealer, widely identified by AV/sandboxes. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-embeds-RealtekHDAudioManager Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable.
References: https://www.virustotal.com/gui/file/249c91245c949e8e7cc7f4bd3d6aef9b354c1d249fc3097b0363862ed7269886, https://tria.ge/240904-zj4b6awckl/behavioral1, https://www.virustotal.com/gui/file/62a7ed6c03d5e519cc5121fe8ad967bdadbbda106a3250b03ab50fb10457ed37, https://tria.ge/240913-pcqgls1cna, https://bad-packages.kam193.eu/pypi/package/larpexodus
Affected packages
Package
Name: larpexodus
Purl: pkg:pypi/larpexodus
Affected ranges
Type: N/A
Events:
