HomeSecurityPyPI suspends new registrations to block malware campaign

PyPI suspends new registrations to block malware campaign

The Python Package Index (PyPI) has temporarily suspended user registrations and the creation of new projectsto address a malware campaign.

See also: Malicious PyPi packages created by Lazarus

PyPI malware campaign

PyPI is a directory for Python projects that helps developers find and install Python packages.

With thousands of packages available, the repository is an attractive target for attackers , who often upload packages with typos or fakes to disrupt software developers and create potential supply chain attacks

Such activity prompted PyPI administrators earlier to announce that new user registrations have been temporarily suspended, to allow for the malware campaign to be addressed.

A report from Checkmarx says that threat actors yesterday began uploading PyPI 365 packages with names that mimic legitimate projects. The packages include malicious code within the 'setup.py' file that is executed during installation, attempting to retrieve an additional payload from a remote server.

To avoid detection, the malicious code is encrypted using the Fernet plugin, with the remote resource URL dynamically constructed when required.

See also: Malicious npm and PyPi packages detected stealing sensitive data from devs

The final payload is an information-stealing tool, with persistence capabilities, that targets data stored in web browsers, such as passwords, cookies , and cryptocurrency extensions.

PyPI suspends new registrations to block malware campaign

Checkmarx has a full list of the malicious entries they found in their report, which includes multiple variants for many legitimate packages. Therefore, PyPi's move to stop the malware campaign is justified.

According to a report by Check Point, the list of malicious packages exceeds 500 and was developed in two stages. The researchers say that each package originated from unique administrator accounts with distinctive names and emails. The researchers say that all entries had the same version number, contained the same malicious code, and the names appeared to be generated through a randomization process.

This incident highlights the importance of software developers and package maintainers using open source repositories to strictly control the authenticity and security of the components they use in their projects.

This is not the first time PyPI has taken such drastic measures to protect its community from malware campaigns. The repository's maintainers took the same action last year, on May 20th.

See also: WhiteSnake Stealer Malware is ported to Windows computers

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

What measures can be taken to combat malware attacks?

One of the most important measures to combat a malware campaign like the one PyPI has identified is to educate and inform users. Users need to be aware of the techniques used by attackers, such as phishing, and be able to recognize suspicious emails and files. It is also vital to use anti-malware software. This software can identify and remove malware before it can cause damage to the system. It is important to update it regularly to be able to deal with the latest threats. The use of advanced security technologies, such as firewalls and intrusion detection and prevention systems (IDS/IPS), can help protect systems from malware attacks. Finally, implementing best practices for managing personal data and information can provide additional protection.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS