Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

glovo-data-platform-declarativePyPI

glovo-data-platform-declarative is a confirmed malicious PyPI package (MAL-2024-5181) that executes malicious code on install (malicious versions 999.9.13, 999.9.15, 999.9.17…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in glovo-data-platform-declarative (PyPI)

MAL-2024-5181
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall glovo-data-platform-declarative

Malicious versions

6 flagged
999.9.13999.9.15999.9.17999.9.18999.9.19999.9.20

Indicators of compromise (SHA-256)

cf78568b9d11046de4810fdb1f8d0bf65417d83bb05adb72e281a42c67f88afd
3597964bc751fa738f7a0a95a3080430fbc44c227ffdb0996125b9a99f5c67c6
38da342d764f6b5af12291c018b3b8df620538dbccbc36fad9cb8e7b5ab12737

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for glovo-data-platform-declarative (6 malicious versions).

  2. If you installed it — respond

    Remove glovo-data-platform-declarative from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If glovo-data-platform-declarative was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. glovo-data-platform-declarative on PyPI has been identified as a malicious package (versions 999.9.13, 999.9.15, 999.9.17, 999.9.18, 999.9.19, 999.9.20 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2024-03963RLUA-2024-08321RLUA-2024-11054

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks glovo-data-platform-declarative-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

glovo-data-platform-declarative (PyPI) malicious package — MAL-2024-5181 | O3 Security