MAL-2024-12246
Dashboard / Malicious Package / MAL-2024-12246
MAL-2024-12246
Published: 8 Sept 2024Last Modified: 12 Dec 2025
Summary: Malicious code in colourfulls (PyPI)
Details: Source: kam193 (735ca3ff38b76e7b11c1f7b884880871427299042e250bb42e17dcf66b8c8e11) Once imported, the module attempts to download an executable, put into Discord directory and most probably trick discord to start it. The download link does not work any more, so it's not possible to say what exactly the remote file did. Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-old-colourfulls Reasons (based on the campaign): - Downloads and executes a remote executable. - typosquatting
Affected packages
Package
Name: colourfulls
Purl: pkg:pypi/colourfulls
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.0
