Malicious code in ysocks (PyPI)
Malware
Published
Jul 21, 2026
to the GitHub Advisory Database
•
Updated Jul 21, 2026
Description
Published to the GitHub Advisory Database
Jul 21, 2026
Reviewed
Jul 21, 2026
Last updated
Jul 21, 2026
Source: checkmarx (ab40ffb51df00b2509d26bc0ce530329b87068e285153fbbd29dd094498625ef)
Attacker distributed 900+ malicious packages via PyPi, infecting local browsers with malicious extension to manipulate clipboard and replace crypto wallet addresses
Credit: OpenSSF (source)
References