PyPI suspends new user registration to block malware campaign
ID: af4a396e-2c50-52da-b09e-258f4d61d031
STIX ID: report--af4a396e-2c50-52da-b09e-258f4d61d031
Feed Name: Bleeping Computer
Threat Score
PyPI temporarily suspended new user registrations and project creation after researchers discovered hundreds of typosquatted packages that include encrypted malicious setup.py code which dynamically constructs a URL to fetch an info‑stealer payload; the campaign (reported as 365–500+ packages) appears automated with unique maintainer accounts and identical malicious versions across packages and targets browser credentials, cookies, and cryptocurrency extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
