logo

Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo

ID: a0400752-9541-5e7f-88cd-4d4fb66506ea

STIX ID: report--a0400752-9541-5e7f-88cd-4d4fb66506ea

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-05-13

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers found a malicious PyPI package named requests-darwin-lite that masqueraded as a fork of the popular requests library and concealed a Golang-based Sliver C2 binary inside an oversized PNG logo; the package decodes and executes a Base64 command on macOS, checks the system UUID to target specific hosts, and was downloaded 417 times before takedown, highlighting a supply-chain malware vector using steganography and conditional execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.