Cybercriminals pose as "helpful" Stack Overflow users to push malware
ID: 8c9ce664-c943-5a74-8b54-e3a952cfa6b4
STIX ID: report--8c9ce664-c943-5a74-8b54-e3a952cfa6b4
Feed Name: Bleeping Computer
Researchers discovered a malicious PyPI package called 'pytoileur' that is part of a known 'Cool package' campaign; the package contains an obfuscated setup.py which, when installed, decodes and executes a command to download and run 'runtime.exe' — a converted Python executable that steals browser cookies, passwords, credit card data and targeted documents. Threat actors have been promoting this package via Stack Overflow answers to trick developers into installing the trojanized package, demonstrating a novel abuse of a trusted developer platform and underscoring the need to verify package sources and inspect code (including with word wrap enabled).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
