A pernicious potpourri of Python packages in PyPI
ID: 4c18f7c7-da3d-5ed8-8412-01934e38cf0c
STIX ID: report--4c18f7c7-da3d-5ed8-8412-01934e38cf0c
Feed Name: WeLiveSecurity (ESET Research)
ESET Research identified a campaign that published 116 malicious Python packages across 53 PyPI projects (over 10,000 downloads) using techniques such as malicious test.py modules, PowerShell in setup.py, or purely malicious packages; these deliver a cross-platform backdoor (Python on Windows, Go on Linux), W4SP stealer variants, and clipboard-stealing malware, with persistence via scheduled tasks on Windows and XDG autostart entries on Linux; the report includes file hashes, a C2 domain, and MITRE ATT&CK mappings and notes that most packages were removed from PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
