logo

A pernicious potpourri of Python packages in PyPI

ID: 4c18f7c7-da3d-5ed8-8412-01934e38cf0c

STIX ID: report--4c18f7c7-da3d-5ed8-8412-01934e38cf0c

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
75/100

Date Published: 2023-12-12

Date Updated: 2026-05-01

...
...

ESET Research identified a campaign that published 116 malicious Python packages across 53 PyPI projects (over 10,000 downloads) using techniques such as malicious test.py modules, PowerShell in setup.py, or purely malicious packages; these deliver a cross-platform backdoor (Python on Windows, Go on Linux), W4SP stealer variants, and clipboard-stealing malware, with persistence via scheduled tasks on Windows and XDG autostart entries on Linux; the report includes file hashes, a C2 domain, and MITRE ATT&CK mappings and notes that most packages were removed from PyPI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.