logo

Over 100 Malicious Packages Target Popular ML PyPi Libraries

ID: 64696320-4104-53c2-bbb3-df466fc26fcd

STIX ID: report--64696320-4104-53c2-bbb3-df466fc26fcd

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2024-03-28

Date Updated: 2026-04-22

Author: Tom Abai

...
...

A Mend.io analysis found over 100 PyPI typosquatting packages impersonating popular machine-learning libraries (e.g., Pytorch, Matplotlib, Selenium). The malicious packages use an encrypted multi-stage payload (Fernet) to fetch and execute obfuscated scripts that steal credentials and Discord tokens, collect and upload cryptocurrency wallet data, replace Electron app.asar files to inject malicious code into wallets (Exodus, Atomic), attempt persistence via startup scripts, and exfiltrate data to attacker-controlled hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.