Malicious PyPI Package Targets E-commerce Sites with Automated Carding Script
ID: bb412ad3-8472-5091-9324-a0198b00771c
STIX ID: report--bb412ad3-8472-5091-9324-a0198b00771c
Feed Name: GBHackers
Security researchers discovered a malicious PyPI package named disgrasya that automates carding attacks against WooCommerce stores using CyberSource: it retrieves a product ID, manipulates the cart, extracts CSRF and CyberSource capture_context tokens from checkout, tokenizes stolen card data, and submits it to validate cards while exfiltrating data to railgunmisaka.com. The package was introduced in version 7.36.9, downloaded over 34,000 times, and although removed from PyPI the technique remains replicable; recommended defenses include fraud rules, CAPTCHA/bot protection, rate-limiting, and monitoring for suspicious checkout patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
