Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package
ID: 10f76f7f-ca0d-53cb-a072-8bca98bc0acf
STIX ID: report--10f76f7f-ca0d-53cb-a072-8bca98bc0acf
Feed Name: The Hacker News
Threat Score
Researchers found a malicious Python package on PyPI named 'pytoileur' that runs a Base64-encoded payload from setup.py to fetch and execute a Windows binary (Runtime.exe), which establishes persistence and deploys spyware and a cryptocurrency stealer; the package was promoted via a fake Stack Overflow account and appears linked to previous bogus Python package campaigns, underscoring supply-chain abuse in open-source ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
