logo

Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines

ID: 183260a1-cf96-5c65-8bf0-134e72859ca6

STIX ID: report--183260a1-cf96-5c65-8bf0-134e72859ca6

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers identified several malicious PyPI packages (eg. nigpal, figflix, telerer, seGMM, fbdebug, sGMM, myGens, NewGends, TestLibs111) uploaded by an actor named “WS” that drop the WhiteSnake Stealer on Windows (and Python harvesters on Linux); the packages hide Base64-encoded PE/Python payloads in setup.py, use Tor for C2, include anti-VM checks, target browsers, crypto wallets and multiple apps, and some implement clipboard clippers to hijack cryptocurrency transactions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.