logo

Over 170K users caught up in poisoned Python package ruse

ID: 094dba0f-011c-5f9f-9ff7-1b612814a0aa

STIX ID: report--094dba0f-011c-5f9f-9ff7-1b612814a0aa

Feed Name: The Register (Security)

Threat Score
82/100

Date Published: 2024-03-25

Date Updated: 2026-04-26

Author: Matthew Connatser

...
...

A coordinated supply-chain campaign used a typosquatted PyPI domain and trojanized Python packages (notably a malicious Colorama) combined with compromised GitHub accounts to insert the fake package URL into popular repositories. The obfuscated malware installed persistently and exfiltrated browser data, Discord app data, crypto wallets, and files matching keywords, potentially affecting users of a large Discord community and thousands of developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.