PyPI Halts Sign-Ups Amid Surge of Malicious Package Uploads Targeting Developers
ID: 89400a76-c305-546e-b232-10b845ae6883
STIX ID: report--89400a76-c305-546e-b232-10b845ae6883
Feed Name: The Hacker News
PyPI was targeted by a large typosquatting campaign (starting March 26, 2024) that uploaded hundreds of malicious packages mimicking popular Python libraries (including ML-related packages). The malicious installers check for Windows, then download an obfuscated stealer from an actor-controlled domain that exfiltrates browser data, Discord tokens, files, and crypto-wallet data, installs a persistence script in Startup, and attempts further payloads; multiple vendors (Checkmarx, Mend.io, Phylum, Check Point) confirmed detections and PyPI temporarily halted new project creation and user sign-ups to mitigate the attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
