Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines
ID: 183260a1-cf96-5c65-8bf0-134e72859ca6
STIX ID: report--183260a1-cf96-5c65-8bf0-134e72859ca6
Feed Name: The Hacker News
Threat Score
Researchers identified several malicious PyPI packages (eg. nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, TestLibs111) uploaded by an actor named “WS” that drop the WhiteSnake Stealer on Windows (and Python harvesters on Linux); the packages hide Base64-encoded PE/Python payloads in setup.py, use Tor for C2, include anti-VM checks, target browsers, crypto wallets and multiple apps, and some implement clipboard clippers to hijack cryptocurrency transactions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
