Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package campaign

2024-10-lokopoil23

The 2024-10-lokopoil23 campaign published 8 malicious PyPI packages. See the full package list, timeline, and how to check whether your dependency tree pulled any of them in.

Malicious packages
8
Advisories
8
Ecosystem
PyPI
First seen
2024-10-16

What to do if you depend on any of these

Every package below was published as malicious under 2024-10-lokopoil23. Treat any machine that installed one as compromised: remove the package and its lockfile entry, rotate every credential the build or runtime could reach (registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values) from a known-clean machine, and audit for unexpected outbound activity.

Because the packages share a campaign, a project that pulled in one has an elevated chance of having pulled in others. Search your lockfiles for 2024-10-lokopoil23 rather than checking a single package name.