ultimate-ai-powerPyPI
Malicious code in ultimate-ai-power (PyPI) Remove it immediately and rotate any exposed credentials.
What this malware does
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
-
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
-
The package overrides the install command in setup.py to execute malicious code during installation.
Malicious versions
Indicators of compromise (SHA-256)
Frequently asked questions
Campaign
References
Credits
- Kamil Mańkowski (kam193) · analyst
Scan your dependencies
O3 Security blocks malicious packages like this at install time and in CI.
Supply-chain protection