Supply-chain threat intelligence

Incident detail

criticalpypi·credential theft·github

Malicious code in youreallydontwantthispackage2131 (PyPI)

youreallydontwantthispackage2131

Risk score

92

AI summary

Indexed incident for youreallydontwantthispackage2131 (pypi).

Description

Installing the package attempts to exfiltrate GCP tokens. As it uses a random names and/or targets specific accounts, it's most probably a (pen)test.


Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.

Campaign: 2024-10-gal32fjdsbf89hnd-gcp-token

Reasons (based on the campaign):

  • exfiltration-cloud-tokens

The OpenSSF Package Analysis project identified 'youreallydontwantthispackage2131' @ 1.0.1 (pypi) as malicious.

It is considered malicious because:

  • The package communicates with a domain associated with malicious activity.

  • The package executes one or more commands associated with malicious behavior.


Credit: OpenSSF (source)

Technical details

Indicators

  • ghsa
    95%

Timeline

  1. Advisory published
  2. Indexed by ThreatPkg

Related incidents