VDB
Sign up
—

MAL-2023-4883

Malicious code in pipurl (PyPI)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: checkmarx (55c6f93c2fe7cf8d698f64469de2621c60440d9176212aae175271be2a414851) EsqueleSquad group published nearly 6000 malicious PyPi and NPM packages, executing spyware and information-stealing malware

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pipurl
Introduced in: 0

No fixed version published yet for pipurl (pip). Pin to a known-safe version or switch to an alternative.

References