Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

pandasproxPyPI

pandasprox is a confirmed malicious PyPI package (MAL-2023-1386) that executes malicious code on install (malicious versions 0.1.4, 0.1.5, 0.1.6…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in pandasprox (PyPI)

MAL-2023-1386
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall pandasprox

What this malware does

The OpenSSF Package Analysis project identified 'pandasprox' @ 0.1.9 (pypi) as malicious.

It is considered malicious because:

  • The package executes one or more commands associated with malicious behavior.

Malicious versions

8 flagged
0.1.40.1.50.1.60.1.70.1.80.1.91.0.01.0.1

Indicators of compromise (SHA-256)

09102fb6db10bc8a136ca7a902415e21c97a31cbf416c904a7efc49a10757320
517ff6909396aac52db13dda18dede377ad26bc8b6520de63d80b8e0e863edce
56fc103fda48c5dbaf029fee3eabebf7c262c43b198ac895e3c8f53206cd7a7a
88f8e65efa15f6cd9e70728303511ef6ae134abf9a8525cafcf8a96deaf64ca7
bafb281b22eb05250a14e7aa19687718b90991a9c0227b2aa3e45512820281f2
bd45123097829e550ce00486343eb5f309448b2ce2924f66acdf3e84d306e17f
c78b8551956b18f93116c90c41f64eaee449422c50d9797f1f0e8d88ad2d0d69
ce2305c61e2ffaa33e2c007f99249dad245932b3862b06bfd12d1ceb306c4d0f

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for pandasprox (8 malicious versions).

  2. If you installed it — respond

    Remove pandasprox from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If pandasprox was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. pandasprox on PyPI has been identified as a malicious package (versions 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.1.9, 1.0.0, 1.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Credits

  • OpenSSF: Package Analysis · finder

Detect & block this

O3 blocks pandasprox-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

pandasprox (PyPI) malicious package — MAL-2023-1386 | O3 Security