logo

PyPI Malware Targets E-commerce Platforms with Fully Automated Carding Toolkit

ID: 03db46bf-3499-5753-90e3-e89ed53254fe

STIX ID: report--03db46bf-3499-5753-90e3-e89ed53254fe

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

A malicious PyPI package named *disgrasya* was discovered that automates credit-card testing and theft (carding) against WooCommerce stores using CyberSource tokenization. The toolkit scrapes product and checkout data, harvests CSRF nonces and CyberSource capture_context, tokenizes stolen card data, submits real checkout requests to validate cards while evading fraud detection, and exfiltrates validated card details to an attacker-controlled server (railgunmisaka.com). The package had over 34,860 downloads and is modular and easy to use, representing a large-scale financial fraud threat; operators are advised to implement layered defenses (fraud rules, bot protection, rate limiting, and traffic monitoring).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.