Malicious Package Affecting pyward package, versions [0,]


Severity

Recommended
0.0
critical
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PYWARD-5889620
  • published8 Sept 2023
  • disclosed7 Sept 2023
  • creditCheckmarx

Introduced: 7 Sep 2023

Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the Pyward package.

Overview

Pyward is a malicious package. This package implements a multi-stage payload delivery and comprehensive data extraction capabilities while using a multitude of techniques to evade detection.

IoC:

  1. hxxps[:]//rentry[.]co/pvtapi/raw

  2. hxxps[:]//api[.]telegram[.]org/bot6470601001:AAFb_C7msjRCEh8jwo_Q74aujh1TXUP0CsQ/sendMessage?chatid=1975115969

  3. hxxps[:]//github[.]com/Hexa-c/Hexa-Grabber

References

CVSS Scores

version 3.1