45K+ Users Victimized By Malicious PyPI Packages
ID: e299ca76-6d5c-5dd4-bed4-9179fb289706
STIX ID: report--e299ca76-6d5c-5dd4-bed4-9179fb289706
Feed Name: Cyble Blog
CRIL investigated a large-scale malicious PyPI campaign where adversaries uploaded over 160 malicious Python packages (including intentionally misspelled names like 'reaquests') to distribute info-stealers and downloaders; the report documents multiple malware families (Creal, W4SP, Hazard Token Grabber, TIKCOCK), obfuscation techniques, evidence of active downloads (~45k total, some packages with hundreds to thousands of installs), and provides extensive IOCs (file hashes, package names) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
