Malicious Package Affecting crytic-compilers package, versions [0,]
Threat Intelligence
Exploit Maturity
Mature
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-CRYTICCOMPILERS-7231128
- published 10 Jun 2024
- disclosed 9 Jun 2024
- credit Ax Sharma
How to fix?
Avoid using all malicious instances of the crytic-compilers
package.
Overview
crytic-compilers is a malicious package. This package uses "typosquatting" to bait unaware users to install it. It contains an information stealer called Lumma (aka LummaC2) and targets mainly Windows machines.
References
CVSS Scores
version 3.1