MAL-2024-5325
Dashboard / Malicious Package / MAL-2024-5325
MAL-2024-5325
Summary: Malicious code in libsock (PyPI)
Details: Source: kam193 (8894e90cf943b19a12209f27fbd96009bc1c0c63af51f723208570e1afae2c47) Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2023-11-update-information-endpoint Reasons (based on the campaign): - obfuscation - The package overrides the install command in setup.py to execute malicious code during installation. - typosquatting
References: https://medium.com/checkmarx-security/python-packages-leverage-github-to-deploy-fileless-malware-b6c281dea58f, https://security.snyk.io/vuln/SNYK-PYTHON-LIBSOCK-6139261, https://bad-packages.kam193.eu/pypi/package/libsock, https://www.reversinglabs.com/blog/malware-leveraging-public-infrastructure-like-github-on-the-rise
Affected packages
Package
Name: libsock
Purl: pkg:pypi/libsock
Affected ranges
Type: N/A
Events:
