Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data
ID: 7ffdfab5-5758-5bea-8bd6-13af24a8c957
STIX ID: report--7ffdfab5-5758-5bea-8bd6-13af24a8c957
Feed Name: HackRead
Threat Score
Fortinet FortiGuard Lab identified two malicious PyPI packages, Zebo-0.1.0 and Cometlogger-0.1, that act as information-stealing malware—logging keystrokes, capturing screenshots, stealing platform tokens/passwords, exfiltrating data, employing obfuscation and anti-VM checks, and establishing persistence via startup scripts—posing a significant risk to developers and systems that install packages from PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
