Malicious PyPI Package Wave Spreads Evolving Supply Chain Attacks
ID: 948b2432-4f51-5ea7-89cf-ac2a289f1a52
STIX ID: report--948b2432-4f51-5ea7-89cf-ac2a289f1a52
Feed Name: securityonline.info
Security researchers uncovered an active PyPI supply‑chain campaign distributing 23 malicious package variants — including typosquats and specialized bioinformatics/AI collections — that use decoupled loaders (langchain-core-mcp), .pth startup hooks and trojanized .abi3.so native extensions to execute a JavaScript payload. The payload harvests high‑value developer artifacts (SSH keys, registry/CI/cloud tokens) enabling attackers to compromise build and release pipelines and inject malicious updates; operators are advised to audit Python environments, check for unapproved .pth and unusual binaries/Bun downloads, rotate tokens, and harden CI build nodes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
