[ << ALL_FEED ]

An attacker published malicious deepseeek and deepseekai packages on the Python Package Index

More in General

Attacker published malicious packages deepseeek and deepseekai on the Python Package Index 🐳

The Supply Chain Security team of the Threat Intelligence department at PT ESC discovered a malicious campaign amid a popular topic of recent days. The attacker, who created the account bvk in June 2023 and had not been active before, registered malicious packages deepseeek and deepseekai on January 29, 2025.

Once installed, the discovered packages steal environment variables when the console commands deepseeek or deepseekai are invoked (screenshot 2). Environment variables are typically valuable because they may contain sensitive data used in the operation of an application, such as access credentials for S3 object storage or other infrastructure resources.

Notably, the code was created using an AI assistant, as indicated by characteristic comments (screenshot 3).

We promptly notified the repository administrators, the packages were quarantined and soon removed. Despite the quick response, they had already been downloaded 36 times by the pip package manager and the bandersnatch mirroring tool, and another 186 times — via browsers, requests, and other means.

Stay vigilant: attackers are constantly looking for such successful names to carry out attacks in open source 🐱.

IoCs:

PyPI package: deepseeek
PyPI package: deepseekai
c2: eoyyiyqubj7mquj.m.pipedream.netCode language: YAML (yaml)


#ti #pypi #pyanalysis #scs
@ptescalator

More from ti_author

More from ti_author

More in General