logo

Malicious PyPI packages targeting highly specific MacOS machines

ID: 5ff73324-e119-5e81-a919-15f46d5408bf

STIX ID: report--5ff73324-e119-5e81-a919-15f46d5408bf

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2024-05-23

Date Updated: 2026-04-27

...
...

DataDog Security Labs reports a cluster of malicious PyPI packages (e.g., reallydonothing, jupyter-calendar-extension) that run code during pip install on macOS systems to search for host-specific secret file paths. If a match is found, the malware deterministically derives a download URL from the secret path, fetches and XOR-decrypts a second-stage binary, writes it to ~/.local/bin, and executes it; different package variants target different filesystem patterns and drop different binaries. The campaign appears targeted and designed to hide infrastructure by deriving payload locations from local filesystem markers; DataDog has published samples, detection heuristics, and an open dataset of malicious packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.