MAL-2024-5221
Dashboard / Malicious Package / MAL-2024-5221
MAL-2024-5221
Summary: Malicious code in httprequesthub (PyPI)
Details: Source: kam193 (9cb098bd2812c755619c73b684023bf34629af2974cb8ef5d522a58be75a571a) Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2023-11-update-information-endpoint Reasons (based on the campaign): - obfuscation - The package overrides the install command in setup.py to execute malicious code during installation. - typosquatting
References: https://medium.com/checkmarx-security/python-packages-leverage-github-to-deploy-fileless-malware-b6c281dea58f, https://security.snyk.io/vuln/SNYK-PYTHON-HTTPREQUESTHUB-6139265, https://bad-packages.kam193.eu/pypi/package/httprequesthub, https://www.reversinglabs.com/blog/malware-leveraging-public-infrastructure-like-github-on-the-rise
Affected packages
Package
Name: httprequesthub
Purl: pkg:pypi/httprequesthub
Affected ranges
Type: N/A
Events:
