logo

PyPi package backdoors Macs using the Sliver pen-testing suite

ID: 4dccc6a5-7075-56ca-870e-2ce890f5cdf5

STIX ID: report--4dccc6a5-7075-56ca-870e-2ce890f5cdf5

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A malicious PyPI package named 'requests-darwin-lite' impersonated the popular requests library to deliver a Sliver C2 Go binary to macOS systems by hiding the binary inside a PNG using steganography and using a UUID check to target specific machines; Phylum discovered the package, reported it, and the malicious versions were removed from PyPI. The report highlights Sliver’s increasing adoption by attackers (including use in BYOVD and ransomware campaigns) and emphasizes the targeted, sophisticated nature of this supply-chain style delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.