Backdoor implant discovered on PyPI posing as debugging utility
ID: 3fb0ed7e-dedb-563d-959b-d087fd95bce4
STIX ID: report--3fb0ed7e-dedb-563d-959b-d087fd95bce4
Feed Name: ReversingLabs Blog
ReversingLabs discovered a malicious PyPI campaign delivering backdoors via packages (dbgpkg, requestsdev and related discordpydebug) that wrap callable functions from requests and socket modules to execute a payload on use; the payload retrieves a public key, installs the Global Socket Toolkit to bypass network controls, and exfiltrates encrypted connection secrets. The technique enabled long‑lasting stealthy access, and RL notes similarities to prior campaigns attributed to the Phoenix Hyena/DumpForums hacktivist group, though attribution remains tentative.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
