logo

Cybercriminals Abuse Stack Overflow to Promote Malicious Python Package

ID: 10f76f7f-ca0d-53cb-a072-8bca98bc0acf

STIX ID: report--10f76f7f-ca0d-53cb-a072-8bca98bc0acf

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-05-29

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers found a malicious Python package on PyPI named 'pytoileur' that runs a Base64-encoded payload from setup.py to fetch and execute a Windows binary (Runtime.exe), which establishes persistence and deploys spyware and a cryptocurrency stealer; the package was promoted via a fake Stack Overflow account and appears linked to previous bogus Python package campaigns, underscoring supply-chain abuse in open-source ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.