Faux ChatGPT, Claude API Packages Deliver JarkaStealer
ID: 1066e196-d090-5bf5-8f9d-7ee7dd26cbea
STIX ID: report--1066e196-d090-5bf5-8f9d-7ee7dd26cbea
Feed Name: Dark Reading
Threat Score
Two malicious PyPI packages, gptplus and claudeai-eng, posed as tools to access ChatGPT and Claude but instead dropped a Java JAR containing the JarkaStealer infostealer; the packages survived on PyPI for about a year, were downloaded over 1,700 times each across multiple countries, and are capable of stealing browser data, session tokens (Telegram, Discord, Steam), and screenshots — a supply-chain style campaign targeting developers and users seeking free GenAI access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
