Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

fef3434334dwrgPyPI

Malicious code in fef3434334dwrg (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2024-5134
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall fef3434334dwrg

What this malware does

Installing the package starts an infostealer

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2023-12-fefeefrrg

Reasons (based on the campaign):

  • infostealer

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • exfiltration-generic

  • exfiltration-browser-data

  • The package contains code to detect if it is running in a sandbox environment.

Malicious versions

1 flagged
1.0

Indicators of compromise (SHA-256)

051e562b712ce090e22977f771a61ec5f8e4a5cb0acbe9a3cf768f68b8533f38
b43476dd93328c77657d0a9c468ce1bad1942932de862b3be02e9010578c6c82
735b89c55992eb74dbad3a7b3391cb73ba8616e88e5d766406550bd97f85ee2c
c2b2e5c701437968432a35bd57be234d6c8f6141a3607819413ae3f88fc0101c
d8a9fd884768864bbfb2bc5eeeee3c82b788fe651fd7cb19763f1953d877761f
dc3d6324966e27e10d8e7cf9c84c82885998d348bcb517982cc02120cfb39c4a

Detection & response playbook

Credential / info stealer
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for fef3434334dwrg (version 1.0). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging fef3434334dwrg across your stack and pipelines.

  2. If you installed it — respond

    fef3434334dwrg is built to steal secrets, so assume every credential the build or runtime could read is compromised. Remove it from your project and lockfile, then rotate ALL exposed secrets — npm/registry tokens, cloud keys, CI/CD secrets, SSH keys, and any .env values — from a known-clean machine. Audit logs for unauthorized use of those credentials.

  3. Did it already run?

    If fef3434334dwrg was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks fef3434334dwrg before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. fef3434334dwrg on PyPI has been identified as a malicious package (version 1.0 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2024-03914RLUA-2024-082702023-12-fefeefrrgRLUA-2026-00318

References

Credits

  • Kamil Mańkowski (kam193)
  • ReversingLabs · finder

Detect & block this

O3 blocks fef3434334dwrg-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the credential exfiltration and severs the channel.

fef3434334dwrg (PyPI) malicious package — MAL-2024-5134 | O3 Security