logo

StackExchange abused to spread malicious PyPi packages as answers

ID: 6963bcb8-f7e9-55f9-bbdc-7cb505d8e8be

STIX ID: report--6963bcb8-f7e9-55f9-bbdc-7cb505d8e8be

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-08-01

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Researchers at Checkmarx uncovered a campaign where threat actors uploaded malicious Python packages to PyPI (e.g., spl-types, raydium, sol-structs, sol-instruct, raydium-sdk), promoted them via StackExchange answers to reach Solana/Raydium developers, and used an update to deliver an info-stealer that harvests browser data, messaging app content, crypto wallet details, targeted files and screenshots and exfiltrates data to a Telegram channel; the packages were downloaded 2,082 times before removal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.