Encyclopedia
PyPI⚠ HIGHtyposquat⚠ ACTIVE THREAT

python3-dateutil

First seen: Apr 8, 2024 0 viewsMimics: python-dateutil
Share threatHN
Threat Description

Typosquat of 'python-dateutil' exploiting the common confusion around Python 2/3 naming. The package enumerates environment variables and the AWS metadata endpoint, shipping credentials to an external collector.

AI Hallucination Analysis
Unlikely AI Hallucination20%
Known to be hallucinated by: n/a (typosquat)
Remediation Guide
  1. Remove 'python3-dateutil' from your dependencies immediately.
  2. Replace with the legitimate package 'python-dateutil'.
  3. Audit your codebase for imports of the malicious package.
  4. Rotate any AWS or cloud credentials that may have been exposed.
Quick Facts
Ecosystem
PyPI
Risk Level
HIGH
Type
typosquat
Status
ACTIVE
Legitimate Package
python-dateutil
Hallucination Confidence
20%
Check My Project
Scan for this package