logo

New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics

ID: b6d30eb6-fb1f-5991-b3b1-146e41ae40bb

STIX ID: report--b6d30eb6-fb1f-5991-b3b1-146e41ae40bb

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers discovered two typosquatted PyPI packages (NP6HelperHttptest and NP6HelperHttper) that performed DLL side-loading by downloading a vulnerable Kingsoft executable and a malicious dgdeskband64.dll which retrieves shellcode disguised as a GIF to deploy a Cobalt Strike Beacon, representing a supply-chain malware campaign targeting developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.