
Two malicious Python libraries , which were discovered to be stealing SSH and GPG keys from developers' projects, have been removed from PyPI (Python Package Index).
The two libraries were the creation of a programmer and imitated other popular Python libraries, while their creator also used the typosquatting to register homonymous names.
One library, called “python3-dateutil”, mimicked the popular “dateutil”, while the second, “jeIlyfish” (the first L is a capital i), mimicked “jeIlyfish”.
German programmer Lukas Martini was the one who discovered the malicious copies last Sunday and notified the security , which immediately removed the libraries.
While python3-dateutil was created and uploaded to PyPI just two days before it was discovered, the library had been available for almost a year, as of December 11, 2018.
As Martini reported, malicious code was only found in the jellyfish library. The latest python3-dateutil did not contain malware itself, but it helped install jellyfish.
The code downloaded a list of fragmented files stored in a GitLab. The nature and purpose of these files was initially unknown, as neither Martini nor the PyPI team had analyzed their behavior in depth before their permanent removal.
Both malicious libraries were uploaded to PyPI by the same developer, who used the username olgired2017.
It is believed that the developer created the copycat to exploit the popularity of the Python library so that he could spread the malicious code more widely. But what he ultimately achieved was to draw more attention to it, which led to its exposure.
The two libraries were exact copies of the normal ones and, except for the malicious code, they worked in exactly the same way.
Because of their similarities, developers who downloaded these libraries into their projects should check their names to see if they have accidentally downloaded duplicates.
If this is the case, all SSH and GPG keys they have used in the last year should be changed.
This is not the first time the PyPI team has had to deal with clones of Python libraries. Similar incidents occurred in September 2017, October 2018, and July 2019.
