Targeted PyPi Package Steals Google Cloud Credentials from macOS Devs
ID: cf686477-da62-53a3-b6f6-3861ab8d53e7
STIX ID: report--cf686477-da62-53a3-b6f6-3861ab8d53e7
Feed Name: Dark Reading
Researchers discovered a malicious PyPI package, "lr-utils-lib," that conceals code in its setup script to run on macOS and target a hard-coded list of 64 specific machines by IOPlatformUUID; it attempts to exfiltrate Google Cloud Platform credentials to a remote server, enabling potential follow-on attacks. The package appears to be a typosquatting/social-engineering campaign (fake LinkedIn persona), and while it was removed from PyPI, it poses a supply-chain risk to any projects that already imported it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
