Malicious Package Affecting podu33332ss package, versions >=0.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Attacked

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-PODU33332SS-11951398
  • published17 Aug 2025
  • disclosed14 Aug 2025
  • creditKirill Boychenko

Introduced: 14 Aug 2025

New Malicious CVE NOT AVAILABLE CWE-506  (opens in a new tab)

How to fix?

Avoid using all malicious instances of the podu33332ss package.

Overview

podu33332ss is a malicious package. This package contains malicious code, and its content was removed from the official package manager. The package appears to be part of a larger campaign targeting user credentials. It, and several other variations, masquerade as automation tools for social media and marketing platforms. When used, a graphical user interface, written in Korean, prompts the user for their credentials. Instead of using these for any legitimate purpose, the package collects the user's MAC address to track infections and sends the credentials to an attacker-controlled server.

CVSS Base Scores

version 4.0
version 3.1