Cybercriminals are abusing Stack Overflow, answering user and promoting a malicious PyPi package that installs info-stealer malware on Windows systems.

Sonatype researcher Ax Sharmadiscovered that this malicious PyPi package is part of an older campaign (Cool package) that targeted Windows last year.
The new malware package is called "pytoileur" and was uploaded to the PyPi repository over the weekend, claiming to be an API management tool.
Malicious packages like this one are often promoted using names similar to other popular packages. This technique is called typo-squatting.
See also: New malware targets ATMs in Europe
However, in this particular case, cybercriminals took a novel approach, answering questions on Stack Overflow and promoting the malware package as a solution.
As Stack Overflow is a popular platform for developers, where many questions are asked and various issues are solved, cybercriminals found the opportunity to exploit it to spread malware by making it look like programming interfaces or libraries.
“We further noticed that a StackOverflow account, “EstAYA G”, created about 2 days ago is now exploiting platform community members seeking help with debugging, directing them to install this malicious package as a “solution” to their problem even though the “solution” is unrelated to the questions posted by the developers,” Sharma explained in report .
The pytoileur package contains a 'setup.py' file that fills a base64 encoded command to be executed with spaces so that it is hidden (unless word wrapping is enabled in the IDE or text file editor).

The command will download an executable file named "runtime.exe" from a remote location and execute it.
See also: Transparent Tribe: Deploys Python, Golang and Rust malware on Indian targets
This executable file is actually a Python program that is converted to .exe and acts as info-stealer malware to steal cookies, passwords ,browser history, credit cards, and other data.
All this information is sent to cybercriminals, who can use it to carry out additional attacks or sell it to other hackers.
We have seen malicious PyPi packages used many times in malware campaigns, but this approach by cybercriminals, where they respond to Stack Overflow to offer supposed solutions, is a very interesting approach.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
One of the main reasons why hackers can abuse Stack Overflow in this way is open nature . Anyone can create an account and post questions or answers, making it easy for malicious actors to band together and spread their malware.
Additionally, the large community on Stack Overflow means that there is always a significant number of users online, increasing the chances of someone falling victim to these attacks.
To protect themselves from these attacks, users should be cautious when running code or installing packages on Stack Overflow. They should thoroughly examine the code and research the package before trusting it. In addition, users can also enable strict security in their browsers to prevent any malicious downloads.
See also: CERT-UA warned of malware campaign from UAC-0006
In conclusion, the misuse of Stack Overflow by cybercriminals to spread malware is a worrying trend. It highlights the need for users to be cautious when using online platforms, even those considered trustworthy and legitimate. It also emphasizes the importance of being informed about cybersecurity best practices and implementing the necessary precautions to protect against such attacks.
Source: www.bleepingcomputer.com
