PyPI Goes Quiet After Huge Malware Attack: 500+ Typosquat Fakes Found
ID: 215f135c-2238-51b0-be86-49fc56d083d7
STIX ID: report--215f135c-2238-51b0-be86-49fc56d083d7
Feed Name: Security Boulevard
PyPI experienced a significant typosquatting/supply-chain campaign in which attackers published over 500 malicious, similarly named Python packages targeting popular libraries (e.g., Pillow, Colorama, requests). The packages contained obfuscated installation-time code that fetched additional payloads and installed an info-stealer with persistence (and ultimately attempted to load a .NET payload identified as zgRAT); PyPI suspended new registrations and removed the packages while multiple vendors published analyses and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
