forked from pypa/advisory-database
-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy pathPYSEC-0000-funcdesc.yaml
More file actions
29 lines (29 loc) · 1.16 KB
/
Copy pathPYSEC-0000-funcdesc.yaml
File metadata and controls
29 lines (29 loc) · 1.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
id: PYSEC-0000-funcdesc.yaml
modified: 2026-06-30T20:24:41Z
published: 2026-06-30T20:24:41Z
summary: Malicious code in funcdesc (PyPI)
aliases:
- MAL-2026-5300
details: |
Part of the "Hades" wave of the Shai-Hulud supply-chain campaign. On 2026-06-08,
malicious phantom releases of funcdesc were published to PyPI using stolen
credentials. The package executes a bundled JavaScript payload (via the Bun
runtime) on import that harvests and exfiltrates credentials and attempts
self-propagation. This entry is a summary; behavior may not be fully
characterized here. See the linked references for detailed analysis and
indicators of compromise.
affected:
- package:
name: funcdesc
ecosystem: PyPI
purl: pkg:pypi/funcdesc
versions:
- 0.2.2
- 0.2.3
references:
- type: EVIDENCE
url: https://inspector.pypi.io/project/funcdesc/0.2.3/packages/ee/07/a3a5d522d90245b00ba11d6f40608c46ce63b4dad69e51f1a197323c4053/funcdesc-0.2.3-py3-none-any.whl//funcdesc-setup.pth
- type: ARTICLE
url: https://www.endorlabs.com/learn/shai-hulud-hades-wave-hits-six-pypi-bioinformatics-packages
- type: ARTICLE
url: https://www.stepsecurity.io/blog/the-hades-campaign-pypi-pack