logo

Cybercriminals pose as "helpful" Stack Overflow users to push malware

ID: 8c9ce664-c943-5a74-8b54-e3a952cfa6b4

STIX ID: report--8c9ce664-c943-5a74-8b54-e3a952cfa6b4

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-05-29

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Researchers discovered a malicious PyPI package called 'pytoileur' that is part of a known 'Cool package' campaign; the package contains an obfuscated setup.py which, when installed, decodes and executes a command to download and run 'runtime.exe' — a converted Python executable that steals browser cookies, passwords, credit card data and targeted documents. Threat actors have been promoting this package via Stack Overflow answers to trick developers into installing the trojanized package, demonstrating a novel abuse of a trusted developer platform and underscoring the need to verify package sources and inspect code (including with word wrap enabled).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.