Vulnerability MAL-2026-17421
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
8 hours ago
October 01, 2026 at 06:58 PM UTC
Malicious code in spo365-graph (PyPI)
1.0.0
1.0.0
Summary
Malicious code in spo365-graph (PyPI)
Details
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-10-spo365-graph
Reasons (based on the campaign):
-
The package overrides the install command in setup.py to execute malicious code during installation.
-
exfiltration-cloud-tokens
-
targetted-attack
-
exfiltration-credentials
References
Impacted packages
Timeline
Published
8 hours ago
October 01, 2026 at 06:58 PM UTC
Last Modified
7 hours ago
October 01, 2026 at 07:45 PM UTC