HomeSecurityMalicious Python package hides Sliver C2 Framework

Malicious Python package hides Sliver C2 Framework

Cybersecurity researchers have discovered a malicious Python package, which was presented as a fork of the popular requests library and was found to be hiding a Golang version of the Sliver command and control framework (C2) inside a PNG image of the project's logo.

python

The package using the steganographic technique is called requests-darwin-lite, which was downloaded 417 times before being removed from the official Python Package Index (PyPI) registry.

Read also: Fake job interviews distribute new Python RAT

“Requests-darwin-lite” turned out to be a variant of the popular requests package, with some significant differences. The most notable of these is the embedding of a malicious Go binary inside an extended version of the requests sidebar PNG logo, as reported by supply chain security firm Phylum.

The package's setup.py file has been updated so that it can now decode and execute a Base64-encoded command to collect the system.

In an interesting twist, the infection process only progresses when the identifier matches a specific value. This suggests that the creators of the malicious package are specifically targeting a system for which they have already determined the identifier through a previous infiltration, suggesting a specialized attack.

This situation creates two possibilities: Either we are facing a highly specialized attack or a test procedure in preparation for a more extensive operation.

Since the UUID matches, requests-darwin-lite reads data from a PNG file named “requests-sidebar-large.png.” This file looks similar to a legitimate requests package that contains a corresponding file named “requests-sidebar.png.”.

The distinguishing feature here is that, while the original logo embedded in requests is just 300 kB in size, the version included in requests-darwin-lite comes in at around 17 MB.

The binary data hidden within the PNG image corresponds to Sliver, an open-source C2 framework based on the Golang programming language, which is designed to be used by security professionals in red team operations.

The ultimate purpose of the package remains unclear, however, its continued development is an indication that open source ecosystems continue to attract interest as platforms for the spread of malware.

python

See also: Telegram fixes zero-day that launches Python scripts

With the majority of software relying on open source, the frequent appearance of malware in npm, PyPI, and other package repositories, especially after the recent XZ Utils incident, highlights the imperative need to systematically address the issues. This approach is critical to avoid potentially destabilizing important parts of the internet.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS