MAL-2024-11657
Dashboard / Malicious Package / MAL-2024-11657
MAL-2024-11657
Summary: Malicious code in pdf2doc (PyPI)
Details: Source: kam193 (ae55659200290f97e3d07c41d49af574eb14ad3dc5913535e8d100cf2c48dd58) During installation, the code attempts to exfiltrate basic data (username, host name) and send to the attacker. The package looks to be a clone of an existing one Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-09-pdf2doc Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - typosquatting - obfuscation - dependency-confusion - The package overrides the install command in setup.py to execute malicious code during installation. - clones-real-package
Affected packages
Package
Name: pdf2doc
Purl: pkg:pypi/pdf2doc
Affected ranges
Type: N/A
Events:
