MAL-2024-5000

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/credential-sdk/MAL-2024-5000.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-5000
Published
2024-06-25T13:34:17Z
Modified
2024-10-24T01:01:58Z
Summary
Malicious code in credential-sdk (PyPI)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2024-03780",
            "modified_time": "2024-06-25T13:34:17Z",
            "versions": [
                "0.0.2"
            ],
            "source": "reversing-labs",
            "import_time": "2024-06-28T02:48:42.617986557Z",
            "sha256": "95c21c47cf7c68c71e0ac9ef9dbe5e9cabd99e9abe092ea459f89720c10cdde0"
        },
        {
            "id": "RLUA-2024-08073",
            "modified_time": "2024-10-16T14:39:03Z",
            "versions": [
                "0.0.1",
                "0.0.3"
            ],
            "source": "reversing-labs",
            "import_time": "2024-10-24T00:59:02.275018371Z",
            "sha256": "a5ad0dfe267e2161bfae2680f4822a1ce1a1d70868f30601c1a1785664df869e"
        }
    ]
}
References
Credits

Affected packages

PyPI / credential-sdk

Package

Affected ranges

Affected versions

0.*
0.0.1
0.0.2
0.0.3

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/credential-sdk/MAL-2024-5000.json"