Supply-chain threat intelligence

Incident detail

criticalpypi·crypto miner·github

Malicious code in xxlsxwriter (PyPI)

xxlsxwriter

Risk score

92

AI summary

Indexed incident for xxlsxwriter (pypi).

Description

Attacker distributed 900+ malicious packages via PyPi, infecting local browsers with malicious extension to manipulate clipboard and replace crypto wallet addresses


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents