Over 170K users caught up in poisoned Python package ruse
ID: 094dba0f-011c-5f9f-9ff7-1b612814a0aa
STIX ID: report--094dba0f-011c-5f9f-9ff7-1b612814a0aa
Feed Name: The Register (Security)
Threat Score
A coordinated supply-chain campaign used a typosquatted PyPI domain and trojanized Python packages (notably a malicious Colorama) combined with compromised GitHub accounts to insert the fake package URL into popular repositories. The obfuscated malware installed persistently and exfiltrated browser data, Discord app data, crypto wallets, and files matching keywords, potentially affecting users of a large Discord community and thousands of developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
