Опубликовано: 30 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5
Описание
gratient 0.5 contains credential harvesting code
gratient is a user-facing library for generating color gradients of text. Version 0.5 contained obfuscated, malicious code targeting Windows platforms, harvesting information and credentials from the user's system and sending them to a remote server. Services may include Mullvad VPN and Telegram.
Ссылки
Пакеты
Наименование
gratient
pip
Затронутые версииВерсия исправления
= 0.5
Отсутствует
8.7 High
CVSS4
7.5 High
CVSS3
8.7 High
CVSS4
7.5 High
CVSS3