Beware Python Developers: Malicious ‘fabrice’ Package Steals AWS Credentials from 37,000+ Downloads
ID: 97589251-8327-5f65-bfdb-399dae79fdf7
STIX ID: report--97589251-8327-5f65-bfdb-399dae79fdf7
Feed Name: securityonline.info
Threat Score
**Executive summary:** The PyPI typosquatted package `fabrice`, impersonating the Fabric SSH library, exfiltrates AWS credentials to a VPN endpoint (89.44.9.227), deploys platform-specific payloads on Linux (hidden ~/.local/bin/vscode, downloaded scripts) and Windows (base64 VBScript -> hidden Python -> executables, scheduled tasks for persistence), and has been downloaded over 37,000 times, risking unauthorized access to cloud resources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
