[ << ALL_FEED ]

First steps in the hacking field

More in General

First steps on the hacking path 🐱

Open source is an interesting environment for observing how projects evolve. It’s fascinating to study the implementation of the early versions of popular libraries like boto3, scikit-learn, requests (the concept plan for version 0.2.0 is quite creative).

It’s also interesting to watch people who, instead of using popular stealers and RATs, try their hand at writing their own solutions.

1️⃣ User SpaceyLad created a chain of two packages:

🟢not-so-evil-package-spaceylad, whose code is shown in screenshots 1 (original version) and 2 (after automatic deobfuscation). This package is responsible for storing a string with the command to download the payload.

🟢not-evil-calculator-spaceylad, which will actually execute the command — screenshot 3.

In the first package, in all versions except 0.0.5, a harmless file with the .css extension is downloaded. If you’re unlucky, a file named evil_python.exe is downloaded from the author’s page on PythonAnywhere, which is actually… calc.exe from the standard Windows programs package. But even in that case, the payload will only execute if the user IXY is present.

One amusing detail — the project releases left in the .idea folder (the project folder in the PyCharm IDE) and the .venv folder (the Python virtual environment folder), which, aside from scant information about the package author, allowed us to learn the original project name — pip_evil_package. Also, thanks to a simple chain of “googling,” it turns out that the developer is a student in the cybersecurity department of a university in Norway 🐈

2️⃣ In July–August 2024, a package called recovery existed, whose purpose according to its description was simple: Checks recovery phone numbers against login page on yahoo. The author’s name, ExodusChecker, raises vague suspicions, but let’s not jump to conclusions.

The first versions of the package look harmless (screenshot 4 — for versions 0.0.1–0.0.3), then the first hints of malicious functionality appear (screenshot 5 — versions 0.0.4–0.0.9). Starting with version 0.1.0, logic appears to replace the resource file for the Exodus crypto wallet (screenshot 6), and starting with version 0.1.4, the attacker learns to attach binary files to the release.

Over the course of 19 releases, the author builds up functionality, gradually turning a proof of concept with absolute paths (hello, user named hammy, testing on Exodus 24.31.4) into universal working code. After that, only QoL work was done. You can see the final result in screenshot 7, which reflects the thirtieth release — 0.3.1. The suckme.bat script saved to the startup folder is a joke in itself.

The app.asar being replaced itself uses a technique previously described by JFrog in Impala Stealer with respect to the .NET NuGet package repository: the unlock function from app/wallet/index.js gains the functionality of sending the seed phrase to the attacker (screenshots 8, 9).

A simple way to protect yourself from this kind of trouble is to use an environment isolated from user files, such as Docker containers. This may not save end users, but developers will be protected to a certain extent from typical attacks. Additionally, you can look into PyAnalysis 😍

We wish you to stay safe from the mischief of attackers in the coming new year 🎂

#ti #pypi #pyanalysis #scs
@ptescalator

More from ti_author

More from ti_author

More in General