HomeSecurityPackage with 34 thousand downloads abuses the WooCommerce API

Package with 34 thousand downloads abuses WooCommerce API

The newly discovered PyPi malicious package named ' disgrasya ' that exploits legitimate WooCommerce stores to validate stolen credit cards has been downloaded over 34,000 times from the open source platform

See also: Malicious PyPI package attacks e-commerce sites

WooCommerce package

The scenario specifically targets WooCommerce stores that use the CyberSource payment gateway for card validation, which is a critical step for carding perpetrators who need to evaluate thousands of stolen cards from dark web leaks and database breaches in order to determine their value and potential exploitation.

Despite the removal of the package from PyPI, the high download numbers demonstrate the widespread abuse of this type of malicious enterprise. Of particular concern is the provocative misuse of PyPi to host a package whose creators clearly stated in the description that it was being used for malicious activities.

Socket reports that the malicious package functionality was introduced in version 7.36.9, likely as an attempt to avoid detection by security checks that may be stricter for initial submissions compared to subsequent updates.

The malicious package includes a Python script that visits legitimate WooCommerce websites, collects product IDs , and then adds items to the cart by calling the store's backend.

See also: Infostealer malware impersonates DeepSeek tools on PyPI

It then navigates to the website's checkout page, where it steals the CSRF token and a capture context, which is a piece of code that CyberSource users use to securely card data.

Package with 34 thousand downloads abuses WooCommerce API
Package with 34 thousand downloads abuses WooCommerce API

Socket says that these two elements are usually hidden on the page and expire quickly, but the script immediately extracts them while filling out the checkout form with false customer information.

In the next step, instead of sending the stolen card directly to the payment gateway, it sends it to a server controlled by the attacker (railgunmisaka.com), which pretends to be CyberSource and returns a fake token for the card.

Finally, the order with the encoded card is submitted to the online store and, if approved, it confirms that the card is valid. In case of failure, it records the error and proceeds to the next card.

Using such a tool, malicious actors have the ability to perform verification of a large volume of stolen credit cards in an automated manner.

These verified cards can then be used to commit financial fraud or sold on cybercrime marketplaces.

See also: Malicious PyPI packages copy AI models to steal data

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

PyPi malicious packages are packages (or libraries) with malicious software uploaded to the Python Package Index (PyPi) , which is the central repository for Python libraries. These packages appear to be useful or perform a specific function, but in fact contain malicious code that can cause damage to the user's computer or exploit the application in which they are installed.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS