MAL-2023-8371

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tencentcloud-python-sdk/MAL-2023-8371.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2023-8371
Published
2023-08-15T06:24:03Z
Modified
2023-10-16T05:42:04Z
Summary
Malicious code in tencentcloud-python-sdk (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Source: checkmarx (c79d20c4af5b69c3506d69fb847d2f5306a83433cb56e391c8dbf828e9728319)

Malicious Typosquatting packages campaign targeting developers, steals cloud service credentials

Source: google-open-source-security (1c2d7813ed56684da76968b382947f78dc954abf5a95371e9752325a8eae3f2c)

Attack targeted at users of Alibaba, AWS and Telegram via malicious packages published to PyPI.

The malicious code was hidden in strategicly chosen functions and would only trigger when these functions were called. The malicious code does not automatically run on install or import, helping the packages evade detection.

Database specific
{
    "iocs": {
        "ips": [
            "119.8.26.163"
        ],
        "urls": [
            "http://119.8.26.163:58888/p/b66886/os11/",
            "https://api.aliyun-sdk-requests.xyz/tencent",
            "https://tg.aliyun-sdk-requests.xyz/telegram",
            "https://api.aliyun-sdk-requests.xyz/aws",
            "https://api.aliyun-sdk-requests.xyz/aliyun"
        ]
    },
    "malicious-packages-origins": [
        {
            "import_time": "2023-10-13T03:24:19.590178782Z",
            "modified_time": "2023-10-13T03:23:13Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "1c2d7813ed56684da76968b382947f78dc954abf5a95371e9752325a8eae3f2c",
            "source": "google-open-source-security"
        },
        {
            "import_time": "2023-10-15T12:42:01.645365881Z",
            "modified_time": "2023-10-15T10:12:58Z",
            "ranges": [
                {
                    "events": [
                        {
                            "introduced": "0"
                        }
                    ],
                    "type": "ECOSYSTEM"
                }
            ],
            "sha256": "c79d20c4af5b69c3506d69fb847d2f5306a83433cb56e391c8dbf828e9728319",
            "source": "checkmarx"
        }
    ]
}
References
Credits

Affected packages

PyPI / tencentcloud-python-sdk

Package

Name
tencentcloud-python-sdk
View open source insights on deps.dev
Purl
pkg:pypi/tencentcloud-python-sdk

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/tencentcloud-python-sdk/MAL-2023-8371.json"