{"id":"MAL-2024-5450","summary":"Malicious code in paintpy (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n","aliases":["SNYK-PYTHON-PAINTPY-3179268"],"modified":"2024-10-24T01:01:58Z","published":"2024-06-25T13:37:55Z","database_specific":{"malicious-packages-origins":[{"id":"RLMA-2024-04232","import_time":"2024-06-28T02:49:35.990027087Z","modified_time":"2024-06-25T13:37:55Z","sha256":"38c13824b7552e8722b08683e99e7946238f7de1f4360aaa16f74034e3d77157","source":"reversing-labs","versions":["2.0"]},{"sha256":"747adc1e65d8aa59e56562f149cee7fb04f763a42cc43307e2e91ee2bd6f93d7","source":"reversing-labs","id":"RLUA-2024-08656","import_time":"2024-10-24T00:59:33.436538878Z","modified_time":"2024-10-16T14:45:07Z"}]},"references":[{"type":"ADVISORY","url":"https://security.snyk.io/vuln/SNYK-PYTHON-PAINTPY-3179268"},{"type":"ARTICLE","url":"https://www.reversinglabs.com/blog/w4sp-continues-to-nest-in-pypi-same-supply-chain-attack-different-distribution-method"},{"type":"ARTICLE","url":"https://blog.sonatype.com/malware-monthly-november-2022"}],"affected":[{"package":{"name":"paintpy","ecosystem":"PyPI","purl":"pkg:pypi/paintpy"},"versions":["2.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/paintpy/MAL-2024-5450.json"}}],"schema_version":"1.7.3","credits":[{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}