HomeSecurityMalicious PyPI packages copy AI models to steal data

Malicious PyPI packages copy AI models to steal data

Cybersecurity researchers have discovered two malicious packages on the Python Package Index (PyPI) repository , posing as popular artificial intelligence models such as OpenAI ChatGPT and Anthropic Claude. Their goal was to distribute an information stealer called JarkaStealer .

pypi

The packages, named gptplus and claudeai-eng, were created by a user named “Xeroline” in November 2023, and had a total of 1,748 and 1,826 downloads, respectively. These packages are no longer available on PyPI. According to a post by Kaspersky, “the malicious packages were created by the same author and differed only in name and description.” They supposedly provided access to the GPT-4 Turbo API and Claude AI API, but contained malicious code that activated the malware upon installation.

The “__init__.py” file in these packages contained Base64-encoded data that installed a Java file (“JavaUpdater.jar”) from a repository on GitHub (“github[.]com/imystorage/storage”). If Java was not already installed on the computer, it downloaded the Java Runtime Environment (JRE) from a URL on Dropbox before executing the JAR file.

The JAR file, known as JarkaStealer, is a Java-based information stealer capable of collecting sensitive information such as browser data, system information, screenshots, and tokens from applications such as Telegram, Discord , and Steam. Ultimately, the collected information is archived, sent to the attacker's server, and deleted from the victim's computer. JarkaStealer is offered as a malware-as-a-service (MaaS) service via a Telegram channel, for a cost of $20 to $50, although the source code has been leaked on GitHub.

pypi

Statistics from ClickPy show that the packages were downloaded primarily by users in the US, China, India, France, Germany and Russia, as part of a year-long supply chain attack campaign. “This discovery highlights the persistent risks of attacks in the software supply chain and the need for increased vigilance when integrating open source components into programming,” said Kaspersky researcher Leonid Bezvershenko.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS