[ << ALL_FEED ]

Catching bug hunters again

More in General

Catching bug hunters again 💀

In one of our previous posts we wrote about traces of bug bounty activity targeting “Yandex”. History repeated itself, but this time with us.

An alert triggered on activity related to new malicious packages innostage and innostage_group. The story is unusual: the developer’s email is jiznetoigra@gmail.com (oh, a Russian-speaking person!), and the payload is downloaded from the domains files.inostage.ru (mimicking innostage-group.ru) and files.pythonhosted.ru (mimicking files.pythonhosted.org).

Big respect to this person: they bothered to buy a domain, and on top of that, probably familiarized themselves with attacks carried out previously… We’re sending a report to the Python Package Index and notifying our colleagues at Innostage.

🐈 We suspect the author read Checkmarx’s March article, where a threat actor “trojanized” the colorama package. A pull request was made that, among other things, replaced the legitimate domain files.pythonhosted.org in distribution links with the attacker-controlled files.pypihosted.org.

Although the project description mentions that this is bug bounty, the person used reverse shells (as shown in the screenshots) as the payload rather than a callback (as the bug hunter from the “Yandex” story did). Not exactly a research approach, unfortunately.

Then, in addition to the innostage and innostage_group packages, cyberart, … posi, maxpatrol, and ptsecurity were added 🤨 Curious. The payload is still the same — reverse shells.

The domain inostage.ru has previously surfaced at Standoff. So once again we’ve discovered bug hunter activity, and this time they’ve also interfered with research 🤬. Well then…

———
PT PyAnalysis. Professionally tracking bug hunters since 2024.

#ti #pypi #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General