logo

Backdoor implant discovered on PyPI posing as debugging utility

ID: 3fb0ed7e-dedb-563d-959b-d087fd95bce4

STIX ID: report--3fb0ed7e-dedb-563d-959b-d087fd95bce4

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2025-05-15

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs discovered a malicious PyPI campaign delivering backdoors via packages (dbgpkg, requestsdev and related discordpydebug) that wrap callable functions from requests and socket modules to execute a payload on use; the payload retrieves a public key, installs the Global Socket Toolkit to bypass network controls, and exfiltrates encrypted connection secrets. The technique enabled long‑lasting stealthy access, and RL notes similarities to prior campaigns attributed to the Phoenix Hyena/DumpForums hacktivist group, though attribution remains tentative.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.