logo

Malicious PyPI Package Targets E-commerce Sites with Automated Carding Script

ID: bb412ad3-8472-5091-9324-a0198b00771c

STIX ID: report--bb412ad3-8472-5091-9324-a0198b00771c

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Security researchers discovered a malicious PyPI package named disgrasya that automates carding attacks against WooCommerce stores using CyberSource: it retrieves a product ID, manipulates the cart, extracts CSRF and CyberSource capture_context tokens from checkout, tokenizes stolen card data, and submits it to validate cards while exfiltrating data to railgunmisaka.com. The package was introduced in version 7.36.9, downloaded over 34,000 times, and although removed from PyPI the technique remains replicable; recommended defenses include fraud rules, CAPTCHA/bot protection, rate-limiting, and monitoring for suspicious checkout patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.