PyPi package backdoors Macs using the Sliver pen-testing suite
ID: 4dccc6a5-7075-56ca-870e-2ce890f5cdf5
STIX ID: report--4dccc6a5-7075-56ca-870e-2ce890f5cdf5
Feed Name: Bleeping Computer
A malicious PyPI package named 'requests-darwin-lite' impersonated the popular requests library to deliver a Sliver C2 Go binary to macOS systems by hiding the binary inside a PNG using steganography and using a UUID check to target specific machines; Phylum discovered the package, reported it, and the malicious versions were removed from PyPI. The report highlights Sliver’s increasing adoption by attackers (including use in BYOVD and ransomware campaigns) and emphasizes the targeted, sophisticated nature of this supply-chain style delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
