logo

Malicious Chimera Turns Larcenous on Python Package Index

ID: d4f961cc-c86d-5b9b-b9d9-63a7a0b6ab44

STIX ID: report--d4f961cc-c86d-5b9b-b9d9-63a7a0b6ab44

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-06-16

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

JFrog researchers discovered a malicious PyPI package, 'chimera-sandbox-extensions', which masqueraded as a Chimera Sandbox add-on and delivered a multistage information-stealing payload that harvested credentials, JAMF receipts, CI/CD and AWS tokens, host and git configuration data. The package used a domain-generation algorithm for resilient C2, authenticated to download a second-stage Python payload, and appears tailored to infiltrate development and cloud environments to enable further supply-chain or CI/CD compromise; the package has been identified and disrupted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.