logo

45K+ Users Victimized By Malicious PyPI Packages

ID: e299ca76-6d5c-5dd4-bed4-9179fb289706

STIX ID: report--e299ca76-6d5c-5dd4-bed4-9179fb289706

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

CRIL investigated a large-scale malicious PyPI campaign where adversaries uploaded over 160 malicious Python packages (including intentionally misspelled names like 'reaquests') to distribute info-stealers and downloaders; the report documents multiple malware families (Creal, W4SP, Hazard Token Grabber, TIKCOCK), obfuscation techniques, evidence of active downloads (~45k total, some packages with hundreds to thousands of installs), and provides extensive IOCs (file hashes, package names) and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.