logo

Beware Python Developers: Malicious ‘fabrice’ Package Steals AWS Credentials from 37,000+ Downloads

ID: 97589251-8327-5f65-bfdb-399dae79fdf7

STIX ID: report--97589251-8327-5f65-bfdb-399dae79fdf7

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2024-11-08

Date Updated: 2026-04-22

Author: do son

...
...

**Executive summary:** The PyPI typosquatted package `fabrice`, impersonating the Fabric SSH library, exfiltrates AWS credentials to a VPN endpoint (89.44.9.227), deploys platform-specific payloads on Linux (hidden ~/.local/bin/vscode, downloaded scripts) and Windows (base64 VBScript -> hidden Python -> executables, scheduled tasks for persistence), and has been downloaded over 37,000 times, risking unauthorized access to cloud resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.