HomeSecurityYet another PyPI package installs malware

Yet another PyPI package installs malware

It looks like yet another PyPI package has been found to be full of malicious malware.

PyPI

In a disturbing discovery, security experts have discovered yet another malicious PyPI package that seeks to obtain users' confidential data and grant unwarranted access to the affected system.

The package, called “colorfool,” was apparently malicious, they said. It contained a “suspiciously large” Python file whose sole mission was to download another file from the Internet and execute it, while making sure to remain hidden from the device user.

See also: BetterHelp: Fined “for sharing customer data”

"The operation, therefore, immediately appeared suspicious and possibly malicious," the report states.

To make matters worse, that wasn't even the only suspicious thing about this file. The URL from which the package is supposed to download the payload was encoded, which is another red flag.

The Python script – code.py – carried information-stealing features such as keystroke logging and cookie extraction. It was also able to steal passwords, kill applications, take screenshots, steal crypto wallet , and even use the webcam .

This PyPI package stands out from other malware that security researchers have found in the past because of its composition. The code was made up of pieces taken from other people's work, often without any regard for the logic or flow of the program. It almost seemed as if the author was indiscriminately copying and pasting pieces of code, leaving behind unnecessary parts that served no purpose in the scheme of things.

See also: Play ransomware: Data stolen from the city of Oakland leaked

Yet another PyPI package installs malware

“The combination of obfuscation along with the malicious code suggests that it is unlikely that all of the code was developed by a single entity ,” the researchers said. “It is likely that the final developer mostly used other people’s code , adding it via copy and paste.”

See also: Flutterwave accounts hacked

For researchers, this is a perfect example of the “democratization of cybercrime,” where threat actors can simply take code from other threat actors and incorporate into their work.

Information source: techradar.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS