PyPI halts new projects, users for 10 hours due to infostealer influx
ID: c58f73fa-3457-5edf-bfed-1d240d0620f2
STIX ID: report--c58f73fa-3457-5edf-bfed-1d240d0620f2
Feed Name: infostealers.com
Threat Score
A large typosquatting campaign on PyPI (27–28 Mar 2024) uploaded many malicious packages whose setup.py executed obfuscated, Fernet-encrypted code on install to download and decrypt an info‑stealer that harvests crypto wallets, browser cookies/extensions and credentials and implements persistence; PyPI temporarily suspended new project creation and registration and numerous malicious packages were removed, with IOCs and a package list provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
