PyPI Malware Targets E-commerce Platforms with Fully Automated Carding Toolkit
ID: 03db46bf-3499-5753-90e3-e89ed53254fe
STIX ID: report--03db46bf-3499-5753-90e3-e89ed53254fe
Feed Name: Cyber Press
A malicious PyPI package named *disgrasya* was discovered that automates credit-card testing and theft (carding) against WooCommerce stores using CyberSource tokenization. The toolkit scrapes product and checkout data, harvests CSRF nonces and CyberSource capture_context, tokenizes stolen card data, submits real checkout requests to validate cards while evading fraud detection, and exfiltrates validated card details to an attacker-controlled server (railgunmisaka.com). The package had over 34,860 downloads and is modular and easy to use, representing a large-scale financial fraud threat; operators are advised to implement layered defenses (fraud rules, bot protection, rate limiting, and traffic monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
