[ << ALL_FEED ]

Adding bookmarks to open-source repositories? Young man, come with us.

More in General

🤨 Adding bookmarks to open-source repositories? Young man, come with us.

As part of threat intelligence, in addition to researching “traditional” malware, we also hunt for backdoors in the Python Package Index repository using the PT PyAnalysis service.

The trend is such that not a week goes by without trojans ☕️. What’s more, attackers upload not only full-featured infostealers, but also their little fledgling attempts.

PT PyAnalysis has smeared the projects of several developers over the past few days; let’s talk about the most interesting creations:

🤔 Screenshots 1, 2. A campaign with an Android stealer containing Arabic comments. It sends files via a Telegram bot (we wrote about how to detect them in your infrastructure’s network traffic here), whose token is hardcoded in the code. The packages have names like raquest, ebell.

🤔 Screenshot 3. A series of clippers (trojans that steal data from the clipboard) masquerading as license checks. They persist on Windows devices by adding an autostart entry to the registry. They listen to the clipboard every second, and if there are changes, they send the data to a Discord channel. The packages have names like testjsonn1, testjson2, gentorqkkh.

🤔 Screenshots 4, 5. A stealer that scans drives in search of .env files, harvests SSH keys from standard paths, and sends all the loot to the attacker’s server using the curl utility. It has logic that depends on the target platform: one for Windows, one for Linux and MacOS. Package: popeye-pip-v3. The developer’s name speaks for itself: shyam_the_hacker.

We notified the Python Package Index, the packages have been whacked 👋

Despite the fact that the names of these packages look unsophisticated and you’re unlikely to make a typo by writing raquest instead of requests, such packages can reach you through transitive dependencies. Building an internal secure mirror is a complex but vitally important element for ensuring modern secure development ❤️

#ti #stealer #pypi #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General