logo

Inside of the WASP's nest: deep dive into PyPI-hosted malware

ID: 05ecc232-e323-55c9-a18d-3f783563c31a

STIX ID: report--05ecc232-e323-55c9-a18d-3f783563c31a

Feed Name: VirusTotal Blog

Threat Score
75/100

Date Published: 2023-06-19

Date Updated: 2026-05-01

Author: Unknown

...
...

This report documents discovery and analysis of dozens of malicious or typosquatted Python packages hosted on PyPI that act primarily as info-stealers — harvesting browser cookies, credentials, Discord tokens, and hijacking cryptocurrency clipboard addresses — with varied sophistication from simple token-grabbers to obfuscated multi-stage droppers (W4SP family, BlackCap, Vespy, etc.). The authors detail TTPs (exfiltration channels such as Discord webhooks/Telegram/Gofile, sandbox checks, clipboard monitoring), provide an extensive appendix of IOCs (many SHA256 hashes, URLs, and IPs), and note widespread code reuse and forking among malware families which increases supply-chain risks for Python developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.