Malicious PyPI Packages Deliver SilentSync RAT
ID: f7a48a6c-3773-5a5f-a82d-60e7965366e3
STIX ID: report--f7a48a6c-3773-5a5f-a82d-60e7965366e3
Feed Name: Zscaler Security Research Blog
Technical analysis of two malicious PyPI packages (sisaws and secmeasure) that masquerade as legitimate libraries for Argentina health services and string sanitization but include backdoor functions which, when invoked with specific tokens, download and execute the SilentSync RAT. The report documents the packages' deceptive behavior, the downloader curl command (pastebin), hardcoded C2 IP (200.58.107.25) and endpoints, persistence techniques for Windows/Linux/macOS, and capabilities for remote command execution, file exfiltration, screenshots, and browser data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
