A malicious PyPi package named “automslc” has recorded over 100,000 downloads in the Python Package Index since 2019, abusing hard-coded credentials to hack music from the Deezer service.
See also: Infostealer malware impersonates DeepSeek tools on PyPI

Deezer is a music streaming service , available in 180 countries, offering access to over 90 million songs, playlists and podcasts. There are two options: a free tier supported by ads and paid subscription plans that offer higher sound quality and offline listening
Security firm Socket has discovered a malicious package that appears to compromise music by encrypting Deezer credentials in order to download media and delete metadata from the platform.
Although hacking tools are not typically categorized as malware, automslc leverages command and control (C2) infrastructure for centralized control, thereby targeting unsuspecting users across a distributed network. It is worth noting that the same tool can be reused for various malicious actions, which means that its users are constantly exposed to risks.
See also: Malicious PyPI packages copy AI models to steal data
At the time of writing this article, automslc is still available for download from PyPI.
The malware includes hard-coded Deezer account credentials, allowing login to the service, or leverages the credentials provided by the user to create a verified connection via its API.
Once logged in, the system requests and parses track metadata and exploits internal decryption tokens, such as the “MD5_ORIGIN” that Deezer uses to generate URLs. The script then uses internal API calls to obtain full-length stream URLs and download the entire audio file, bypassing the 30-second preview available through Deezer’s public access.

Downloaded audio files are stored locally on your device in high quality, allowing you to listen and share them offline. This practice violates both Deezer's terms of use and copyright law, exposing users to risk without them knowing it.
The PyPi automslc package has the ability to request and download files in a continuous stream, effectively allowing illegal copying on a large scale.
See also: Malicious PyPi packages mimic ChatGPT, steal developer data
Music piracy is one of the most serious problems of the digital age, affecting both creators and distribution platforms. Many users resort to unofficial sources to access the music they love, underestimating the consequences of this act. Let's see how you can protect your personal data and support artists, while avoiding legal troubles.
- Use Official Platforms: Platforms like Spotify or Apple Music offer access to music legally. By avoiding unofficial sources, you reduce the risk of exposure to malware or viruses.
- Check Security Settings: Ensure that your computer has up-to-date security software and an enabled firewall to block online threats.
- Avoid Questionable Websites: Websites that offer free music are often sources of risk for phishing attacks, which aim to steal your information.
- VPN Application: Using a Virtual Private Network (VPN) can protect your data as you browse the internet, offering additional layers of security.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
