{"id":"MAL-2024-5119","summary":"Malicious code in ethter (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","aliases":["SNYK-PYTHON-ETHTER-5820011"],"modified":"2024-10-24T01:01:58Z","published":"2024-06-25T13:35:14Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2024-03899","import_time":"2024-06-28T02:48:56.334895752Z","modified_time":"2024-06-25T13:35:14Z","sha256":"f137992da09b5637dc843664e5d25112299005dff109cdf33b64def3981d0e65","source":"reversing-labs","versions":["0.9.1b1","1.10.1b1"]},{"source":"reversing-labs","id":"RLUA-2024-08248","import_time":"2024-10-24T00:59:10.90297542Z","modified_time":"2024-10-16T14:40:53Z","sha256":"744d9ef520697b3136e3cda9ea59c6b4c275129a83d5f6bf5a29f4e27c09f583"}]},"references":[{"type":"ARTICLE","url":"https://blog.sonatype.com/malicious-pypi-package-vmconnect-imitates-vmware-vsphere-connector-module"},{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-PYTHON-ETHTER-5820011"},{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/vmconnect-malicious-pypi-packages-imitate-popular-open-source-modules"}],"affected":[{"package":{"name":"ethter","ecosystem":"PyPI","purl":"pkg:pypi/ethter"},"versions":["0.9.1b1","1.10.1b1"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/ethter/MAL-2024-5119.json"}}],"schema_version":"1.7.3","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}