logo

Malicious PyPI package with 37,000 downloads steals AWS keys

ID: 3a115a48-632e-5862-9026-c6170d168d6e

STIX ID: report--3a115a48-632e-5862-9026-c6170d168d6e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious PyPI package called 'fabrice' — a typosquat of the popular 'fabric' library — was published since 2021 and downloaded over 37,000 times; it installs OS-specific payloads (Linux shell scripts and Windows VBScript/Python binaries) to maintain persistence and uses boto3 to harvest AWS credentials, exfiltrating them to an attacker-operated server, with recommendations to verify package names and secure AWS IAM and credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.