logo

Beware: 3 Malicious PyPI Packages Found Targeting Linux with Crypto Miners

ID: a50efa29-6aa1-595a-823b-9d500e60621e

STIX ID: report--a50efa29-6aa1-595a-823b-9d500e60621e

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-01-04

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Three malicious Python packages (modularseven, driftme, catme) published to PyPI were discovered to deploy a CoinMiner on Linux systems. The packages decode and fetch a first-stage shell script that retrieves configuration and an ELF miner hosted remotely (GitLab and papiculo.net), execute the binary with nohup to run in the background, and ensure persistence by inserting commands into ~/.bashrc; they attracted 431 downloads before takedown and show code reuse and staging techniques similar to a prior culturestreak campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.