Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

pipcoloringsPyPI

Malicious code in pipcolorings (PyPI) Remove it immediately and rotate any exposed credentials.

MAL-2024-5490
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall pipcolorings

Malicious versions

1 flagged
0.0.1

Indicators of compromise (SHA-256)

cffff28ce53c7a815e615773bf0e7b7a2d7255a709d3558030e1b8985ba2bc12
19900d1a68f2178c12ead50d90fa6e7a45af91c3fe34e50c415b69108007379b

Detection & response playbook

Malicious package
  1. Find it

    Scan your lockfiles (package-lock.json, pnpm-lock.yaml, yarn.lock, requirements.txt, poetry.lock, etc.) and build artifacts for pipcolorings (version 0.0.1). O3 Security's supply-chain scanner checks every dependency against known-malicious package intelligence at install time and in CI, flagging pipcolorings across your stack and pipelines.

  2. If you installed it — respond

    Remove pipcolorings from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If pipcolorings was ever installed, its post-install/runtime payload may have already executed. O3's L7 egress monitoring and runtime eBPF sensors detect the credential exfiltration or command-and-control callback after install and block the malicious outbound channel, so you catch and contain the actual compromise — not just the presence of the package.

  4. How O3 protects you

    O3 blocks pipcolorings before install through its supply-chain scanner, and if it has already run, detects and severs the exfiltration or C2 callback at runtime through L7 egress monitoring and eBPF.

Frequently asked questions

No. pipcolorings on PyPI has been identified as a malicious package (version 0.0.1 flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2024-04272RLUA-2024-08700

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks pipcolorings-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

pipcolorings (PyPI) malicious package — MAL-2024-5490 | O3 Security