Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Malicious package

pyserealPyPI

pysereal is a confirmed malicious PyPI package (MAL-2024-5771) that executes malicious code on install (malicious versions 0.0.4, 0.0.6, 0.0.7…). Do not install it — remove it immediately and rotate any exposed credentials.

Malicious code in pysereal (PyPI)

MAL-2024-5771
Immediate action
Remove the package, then rotate any secrets the build/runtime could reach.
pip uninstall pysereal

Malicious versions

13 flagged
0.0.40.0.60.0.70.0.90.1.00.1.10.1.20.1.30.1.40.1.50.1.60.1.70.1.8

Indicators of compromise (SHA-256)

097ffb440443616bf0649e43ee31ac98ff0b2e7e63b36e57f7051cbe2ed71bc4
c6fc0e3d6625c119dd0e9979b959ec44a78c649821755ebf863382714426cdf9

Detection & response playbook

Malicious package
  1. Find it

    Search your lockfiles and build artifacts for pysereal (13 malicious versions).

  2. If you installed it — respond

    Remove pysereal from your project and lockfile, then assume any secrets accessible to the build or runtime were exposed: rotate API keys, tokens, and credentials, and audit for unexpected outbound activity or persistence.

  3. Did it already run?

    If pysereal was installed, its post-install payload may already have run. Removing the package does not undo that — check outbound connections and credential use from the install window onward.

Frequently asked questions

No. pysereal on PyPI has been identified as a malicious package (versions 0.0.4, 0.0.6, 0.0.7, 0.0.9, 0.1.0, 0.1.1, 0.1.2, 0.1.3, and 5 more flagged). It should be removed immediately — do not install or keep it in your dependency tree.

Campaign

RLMA-2024-04567RLUA-2024-08997

Credits

  • ReversingLabs · finder

Detect & block this

O3 blocks pysereal-class packages before install and in CI — and if it already ran, its runtime egress monitoring catches the malicious outbound activity and severs the channel.

Explore

pysereal (PyPI) malicious package — MAL-2024-5771 | O3 Security