Supply-chain threat intelligence

Incident detail

criticalpypi·malware·github

Malicious code in yc-as-client (PyPI)

yc-as-client

Risk score

92

AI summary

Indexed incident for yc-as-client (pypi).

Description

The OpenSSF Package Analysis project identified 'yc-as-client' @ 11.11.3 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents