{"id":"MAL-2024-5044","summary":"Malicious code in devicespoofer (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","aliases":["SNYK-PYTHON-DEVICESPOOFER-3179237"],"modified":"2024-10-24T01:01:58Z","published":"2024-06-25T13:34:38Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2024-03824","import_time":"2024-06-28T02:48:47.588015123Z","modified_time":"2024-06-25T13:34:38Z","sha256":"270a7619d70b5776acc0e4fe4ade36a596fc55f6b42b880f80419915c823cb52","source":"reversing-labs","versions":["2.0","2.2"]},{"modified_time":"2024-10-16T14:39:32Z","sha256":"93a947a0f59a007053e8b94b95b0aad27e9d8daf500d61694b81cec5b8c881ff","source":"reversing-labs","id":"RLUA-2024-08120","import_time":"2024-10-24T00:59:05.630660625Z"}]},"references":[{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-PYTHON-DEVICESPOOFER-3179237"},{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/w4sp-continues-to-nest-in-pypi-same-supply-chain-attack-different-distribution-method"},{"type":"ARTICLE","url":"https://blog.sonatype.com/malware-monthly-november-2022"}],"affected":[{"package":{"name":"devicespoofer","ecosystem":"PyPI","purl":"pkg:pypi/devicespoofer"},"versions":["2.0","2.2"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/devicespoofer/MAL-2024-5044.json"}}],"schema_version":"1.7.3","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}