Malicious PyPI packages targeting highly specific MacOS machines
ID: 5ff73324-e119-5e81-a919-15f46d5408bf
STIX ID: report--5ff73324-e119-5e81-a919-15f46d5408bf
Feed Name: Datadog Security Labs
DataDog Security Labs reports a cluster of malicious PyPI packages (e.g., reallydonothing, jupyter-calendar-extension) that run code during pip install on macOS systems to search for host-specific secret file paths. If a match is found, the malware deterministically derives a download URL from the secret path, fetches and XOR-decrypts a second-stage binary, writes it to ~/.local/bin, and executes it; different package variants target different filesystem patterns and drop different binaries. The campaign appears targeted and designed to hide infrastructure by deriving payload locations from local filesystem markers; DataDog has published samples, detection heuristics, and an open dataset of malicious packages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
