2024-08-embeds-RealtekHDAudioManager
The 2024-08-embeds-RealtekHDAudioManager campaign published 40 malicious PyPI packages. See the full package list, timeline, and how to check whether your dependency tree pulled any of them in.
What to do if you depend on any of these
Every package below was published as malicious under 2024-08-embeds-RealtekHDAudioManager. Treat any machine that installed one as compromised: remove the package and its lockfile entry, rotate every credential the build or runtime could reach (registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values) from a known-clean machine, and audit for unexpected outbound activity.
Because the packages share a campaign, a project that pulled in one has an elevated chance of having pulled in others. Search your lockfiles for 2024-08-embeds-RealtekHDAudioManager rather than checking a single package name.
- antibyfronView advisory →
- artindexView advisory →
- automsgView advisory →
- cblinesView advisory →
- cryptocallsView advisory →
- dahoodView advisory →
- discouldView advisory →
- embedsView advisory →
- ezautoView advisory →
- haaahhahaView advisory →
- hahahasillyxdView advisory →
- larpexodusView advisory →
- lowuiView advisory →
- modeflowView advisory →
- mumupatcherView advisory →
- mumuplayer12View advisory →
- nezurView advisory →
- partpythView advisory →
- pyaacvView advisory →
- pyaddView advisory →
- pycblinesView advisory →
- pycordapiView advisory →
- pydeobfView advisory →
- pydllcfgView advisory →
- pykaneView advisory →
- pyloyView advisory →
- pymatchaView advisory →
- pysleekView advisory →
- pysolaraView advisory →
- pytkitView advisory →
- pytrvView advisory →
- pytskcheckView advisory →
- pyvantqView advisory →
- rodllView advisory →
- roinjectView advisory →
- rolibView advisory →
- solaraundView advisory →
- uidesignView advisory →
- websendView advisory →
- xsilyxdView advisory →