Cybersecurity researchers have identified a malicious Python package uploaded to the Python Package Index (PyPI) called Lumma (also known as LummaC2), designed to steal information.

The package, called crytic-compilers, is a variant of the legitimate crytic-compile library. The malicious package was downloaded 441 times before being removed by PyPI maintainers.
See also: PyPi package used as backdoor on macOS devices
“The fake library is interesting not only because of its name, which is derived from the legitimate Python tool `crytic-compile`, but also because of the alignment of the version numbers with the real library,” said Sonatype security researcher Ax Sharma. “While the latest version of the real library stops at 0.3.7, the fake `crytic-compilers` appears up to version 0.3.11 — giving the impression that it is a newer version.”.
In a further attempt to preserve this technique, some versions of crytic-compilers (e.g. 0.3.9) were found to install the actual package via a modification to the setup.py script.
The latest version, however, rejects any pretense of being a benign library. It detects whether the operating system is Windows and, if so, launches an executable file (“s.exe”), which is designed to download additional payloads, including the Lumma Stealer.
An information thief made available to other criminals under the malware- as-a-service (MaaS) model, Lumma has been distributed through a variety of methods, including trojanized software, bad advertising, and even fake browser updates.
The discovery “highlights experienced threat actors now targeting Python, exploiting open source registries like PyPI as a distribution channel for their powerful data theft arsenal,” Sharma said.
Fake browser update campaigns target hundreds of WordPress websites
Sucuri has revealed that over 300 WordPress sites have been compromised with malicious Google Chrome update pop-ups. These redirect visitors to fake MSIX installers, which install information-stealing programs and remote access trojans
The attack chains involve threat actors gaining unauthorized access to the WordPress admin interface and installing a legitimate plugin called Hustle – Email Marketing, Lead Generation, Optins, Popups. In doing so, they upload code responsible for displaying fake browser update pop-ups.
Read more: Transparent Tribe: Deploys Python, Golang and Rust malware on Indian targets
“This campaign highlights a growing trend among hackers who are exploiting legitimate plugins for malicious purposes,” explained security researcher Puja Srivastava. “This way, they avoid detection by file scanners, as most plugins store their data in the WordPress database.”.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
