MAL-2024-5326
Dashboard / Malicious Package / MAL-2024-5326
MAL-2024-5326
Summary: Malicious code in libsocks5 (PyPI)
Details: Source: kam193 (f9d745820f944dd4aaf916168db7546fdd4689ac873f85166e92e87329caa3f9) Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2023-11-update-information-endpoint Reasons (based on the campaign): - obfuscation - The package overrides the install command in setup.py to execute malicious code during installation. - typosquatting
References: https://security.snyk.io/vuln/SNYK-PYTHON-LIBSOCKS5-6139260, https://medium.com/checkmarx-security/python-packages-leverage-github-to-deploy-fileless-malware-b6c281dea58f, https://bad-packages.kam193.eu/pypi/package/libsocks5, https://www.reversinglabs.com/blog/malware-leveraging-public-infrastructure-like-github-on-the-rise
Affected packages
Package
Name: libsocks5
Purl: pkg:pypi/libsocks5
Affected ranges
Type: N/A
Events:
