logo

Malicious PyPI Packages Deliver SilentSync RAT

ID: f7a48a6c-3773-5a5f-a82d-60e7965366e3

STIX ID: report--f7a48a6c-3773-5a5f-a82d-60e7965366e3

Feed Name: Zscaler Security Research Blog

Threat Score
78/100

Date Published: 2025-09-19

Date Updated: 2026-05-01

...
...

Technical analysis of two malicious PyPI packages (sisaws and secmeasure) that masquerade as legitimate libraries for Argentina health services and string sanitization but include backdoor functions which, when invoked with specific tokens, download and execute the SilentSync RAT. The report documents the packages' deceptive behavior, the downloader curl command (pastebin), hardcoded C2 IP (200.58.107.25) and endpoints, persistence techniques for Windows/Linux/macOS, and capabilities for remote command execution, file exfiltration, screenshots, and browser data theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.