Hackers uploaded malicious Python to the PyPI repository and promoted them through the online question and answer platform StackExchange.
See also: Hackers target Python developers with fake “Crytic-Compilers” package on PyPI

The malicious PyPI packages, called “spl-types”, “raydium”, “sol-structs”, “sol-instruct” and “raydium-sdk” , download scripts that steal sensitive data from the browser, messaging apps (Telegram, Signal, Session) and cryptocurrency wallet details (Exodus, Electrum, Monero).
The information-stealing malware can also infiltrate files with specific keywords, as well as take screenshots and send all the data to a Telegram channel.
Researchers at application security testing firm Checkmarx say that while the packages were uploaded to PyPI on June 25, they received the malicious component in an update on July 3. The packages are no longer on PyPI and have already been downloaded 2082 times.
According to Checkmarx's research, the attackers specifically targeted users involved in the Raydium and Solana.
The fact that Raydium does not have a Python library created an exploit opportunity for attackers, who used the name for their package without having to resort to typosquatting or other deception techniques.
To promote the malicious PyPI packages to the right targets, the attackers created accounts on StackExchange and left comments under popular threads containing links to the malicious packages.
See also: PyPi package used as backdoor on macOS devices
The selected topics were related to the package names and the answers provided were of high quality, so victims could be tempted to download the dangerous packages.

With over two thousand potential infections, estimating the impact of this campaign is difficult, but Checkmarx researchers presented some examples of victims in their report.
One case involves an IT employee whose Solana cryptocurrency wallet was drained as a result of the infection.
In the second example, the malware captured a screenshot of the victim's private key, which can be used to bypass MFA protections and compromise accounts even without the password.
Specifically, this screenshot shows that Windows antivirus and threat scans failed to catch the threat running on the victim's device.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Inspecting the code before using it is the best way to ensure that it has not been modified for malicious purposes, as was the case in the campaign described by Checkmarx.
See also: PyPI suspends new registrations to block malware campaign
Malicious Python packages pose significant risks to both developers and organizations, often masquerading as legitimate libraries to exploit vulnerabilities in applications. These packages can be intended to steal sensitive information, install malware, or create backdoors for unauthorized access. Attackers often use popular repositories, such as PyPI, to upload these malicious packages, as in the case of the StackExchange platform. To mitigate these risks, it is important to adopt strict validation processes for package sourcing, regularly audit, and stay informed of known threats in the Python ecosystem.
Source: bleepingcomputer
