logo

Python downloader highlights noise problem in open source threat detection

ID: 6f91cf4d-75ac-5fec-83c9-a1cce3ca5f7d

STIX ID: report--6f91cf4d-75ac-5fec-83c9-a1cce3ca5f7d

Feed Name: ReversingLabs Blog

Threat Score
35/100

Date Published: 2024-06-05

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs discovered a malicious PyPI package, xFileSyncerx, that fetched second- and third-stage Python scripts (s2.py and s3.py) from GitHub; s2.py implemented a wiper that encrypted files under /home and attempted lateral movement via SSH with hard-coded credentials. The code appeared rudimentary and targeted, and the repository author later confirmed the tools were used in a red-team engagement; the PyPI package and GitHub files were removed. The report highlights the challenge of distinguishing malicious packages from red-team or grayware noise in open-source repositories and includes IoCs (PyPI package and raw GitHub URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.