logo

Targeted PyPi Package Steals Google Cloud Credentials from macOS Devs

ID: cf686477-da62-53a3-b6f6-3861ab8d53e7

STIX ID: report--cf686477-da62-53a3-b6f6-3861ab8d53e7

Feed Name: Dark Reading

Threat Score
68/100

Date Published: 2024-07-26

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers discovered a malicious PyPI package, "lr-utils-lib," that conceals code in its setup script to run on macOS and target a hard-coded list of 64 specific machines by IOPlatformUUID; it attempts to exfiltrate Google Cloud Platform credentials to a remote server, enabling potential follow-on attacks. The package appears to be a typosquatting/social-engineering campaign (fake LinkedIn persona), and while it was removed from PyPI, it poses a supply-chain risk to any projects that already imported it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.