New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics
ID: b6d30eb6-fb1f-5991-b3b1-146e41ae40bb
STIX ID: report--b6d30eb6-fb1f-5991-b3b1-146e41ae40bb
Feed Name: The Hacker News
Threat Score
Researchers discovered two typosquatted PyPI packages (NP6HelperHttptest and NP6HelperHttper) that performed DLL side-loading by downloading a vulnerable Kingsoft executable and a malicious dgdeskband64.dll which retrieves shellcode disguised as a GIF to deploy a Cobalt Strike Beacon, representing a supply-chain malware campaign targeting developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
