Vulnerability MAL-2026-17421

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 01, 2026 at 06:58 PM UTC
Malicious code in spo365-graph (PyPI)
1.0.0
1.0.0

Summary

Malicious code in spo365-graph (PyPI)

Details

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-10-spo365-graph

Reasons (based on the campaign):

  • The package overrides the install command in setup.py to execute malicious code during installation.

  • exfiltration-cloud-tokens

  • targetted-attack

  • exfiltration-credentials

Impacted packages

Timeline

Published
8 hours ago
October 01, 2026 at 06:58 PM UTC
Last Modified
7 hours ago
October 01, 2026 at 07:45 PM UTC