PyPi package with 100K installs pirated music from Deezer for years
ID: 6b4182dc-9eaf-56a2-887f-26bbde17ff88
STIX ID: report--6b4182dc-9eaf-56a2-887f-26bbde17ff88
Feed Name: Bleeping Computer
Threat Score
A malicious PyPI package called 'automslc' — downloaded over 100,000 times — abuses hard-coded Deezer credentials and internal API tokens to retrieve and store full-length audio files, uses C2 infrastructure for centralized control, remains available on PyPI, and could be repurposed for broader malicious activity, exposing users to legal and security risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
