HomeSecurityStackExchange spreads malicious PyPi packages through replies

StackExchange spreads malicious PyPi packages through answers

Hackers uploaded malicious Python to the PyPI repository and promoted them through the online question and answer platform StackExchange.

See also: Hackers target Python developers with fake “Crytic-Compilers” package on PyPI

StackExchange malicious PyPi

The malicious PyPI packages, called “spl-types”, “raydium”, “sol-structs”, “sol-instruct” and “raydium-sdk” , download scripts that steal sensitive data from the browser, messaging apps (Telegram, Signal, Session) and cryptocurrency wallet details (Exodus, Electrum, Monero).

The information-stealing malware can also infiltrate files with specific keywords, as well as take screenshots and send all the data to a Telegram channel.

Researchers at application security testing firm Checkmarx say that while the packages were uploaded to PyPI on June 25, they received the malicious component in an update on July 3. The packages are no longer on PyPI and have already been downloaded 2082 times.

According to Checkmarx's research, the attackers specifically targeted users involved in the Raydium and Solana.

The fact that Raydium does not have a Python library created an exploit opportunity for attackers, who used the name for their package without having to resort to typosquatting or other deception techniques.

To promote the malicious PyPI packages to the right targets, the attackers created accounts on StackExchange and left comments under popular threads containing links to the malicious packages.

See also: PyPi package used as backdoor on macOS devices

The selected topics were related to the package names and the answers provided were of high quality, so victims could be tempted to download the dangerous packages.

StackExchange spreads malicious PyPi packages through answers

With over two thousand potential infections, estimating the impact of this campaign is difficult, but Checkmarx researchers presented some examples of victims in their report.

One case involves an IT employee whose Solana cryptocurrency wallet was drained as a result of the infection.

In the second example, the malware captured a screenshot of the victim's private key, which can be used to bypass MFA protections and compromise accounts even without the password.

Specifically, this screenshot shows that Windows antivirus and threat scans failed to catch the threat running on the victim's device.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Inspecting the code before using it is the best way to ensure that it has not been modified for malicious purposes, as was the case in the campaign described by Checkmarx.

See also: PyPI suspends new registrations to block malware campaign

Malicious Python packages pose significant risks to both developers and organizations, often masquerading as legitimate libraries to exploit vulnerabilities in applications. These packages can be intended to steal sensitive information, install malware, or create backdoors for unauthorized access. Attackers often use popular repositories, such as PyPI, to upload these malicious packages, as in the case of the StackExchange platform. To mitigate these risks, it is important to adopt strict validation processes for package sourcing, regularly audit, and stay informed of known threats in the Python ecosystem.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS