MAL-2024-5323
Dashboard / Malicious Package / MAL-2024-5323
MAL-2024-5323
Summary: Malicious code in libproxy (PyPI)
Details: Source: kam193 (cd7d095572ec4dd86648a86d8a9ee88e4c5b11e02bc519a951d3c41539d6e6c0) Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2023-11-update-information-endpoint Reasons (based on the campaign): - obfuscation - The package overrides the install command in setup.py to execute malicious code during installation. - typosquatting
References: https://medium.com/checkmarx-security/python-packages-leverage-github-to-deploy-fileless-malware-b6c281dea58f, https://security.snyk.io/vuln/SNYK-PYTHON-LIBPROXY-6139262, https://bad-packages.kam193.eu/pypi/package/libproxy, https://www.reversinglabs.com/blog/malware-leveraging-public-infrastructure-like-github-on-the-rise
Affected packages
Package
Name: libproxy
Purl: pkg:pypi/libproxy
Affected ranges
Type: N/A
Events:
