In recent days, several malicious packages have been discovered in the PyPI repository for Python projects that have turned programmers' workstations into cryptomining machines.
See also: Python Package Index (PyPI) and GitLab under spam attacks

All the malicious packages were published by the same account and tricked various developers into downloading them thousands of times, using names of legitimate Python projects, which were however misspelled.
A total of six packages containing malicious code infiltrated the Python Package Index (PyPI) in April:
- maratlib
- maratlib1
- matplatlib-plus
- mllearnlib
- mplatlib
- learninglib
All six came from the user “nedog123” and the names of most of them are related to the legitimate plotting software, matplotlib (but they are not spelled correctly).
Ax Sharma, a security researcher at Sonatype ,analyzed the “maratlib” package, noting that it was used as a dependency by the other malicious components.
“For each of these packages, the malicious code is included in the setup.py file, which is a build script that is executed when a package is installed,” the researcher writes.
While analyzing the package, the researcher also discovered that maratlib was attempting to download a Bash script (aza2.sh) from a GitHub repository that is no longer available.
Through his analysis, Sharma found that the script's role was to run a cryptominer called "Ubqminer" on the compromised computer.
See also: Hackers install cryptomining malware on unpatched Microsoft Exchange servers

The researcher also reported that the malware replaced the default Kryptex wallet address with his own for mining the Ubiq cryptocurrency (UBQ).
In another variation, the script included a different cryptomining program that uses GPU power, the open-source T-Rex.
See also: Windows and Linux devices are attacked by a new cryptomining worm
Attackers often target open-source code repositories, such as PyPI, NPM for NodeJS , or RubyGems.
In this case, the six malicious packages were detected by Sonatype after scanning the PyPI repository with its automated malware detection system, Release Integrity. At the time of their detection, the malicious packages had accumulated nearly 5,000 downloads (since April), with “maratlib” recording the highest number of downloads, 2,371.
Source: Bleeping Computer
