The city celebrates, the mafia wakes up

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Between January 1 and 11, approximately 180 malicious packages were removed from the NPM ecosystem, and 16 from PyPI.
On January 4, user
ambertransit published a project called aiihttp, whose name mimics the http client aiohttp.The code begins with simple obfuscation:
import base64
exec(base64.b64decode('aW1wb3J0IGl...')Code language: Python (python)The logic hidden behind base64 is shown in the first screenshot. Key points:
• The package gentlemanly helps the developer who made a typo: it deletes itself, installs
aiohttp [item 1 in screenshot 1], then reloads the module if it was already imported [2].• The next stage is hosted on GitHub [3]. However, it’s not that simple — it’s encrypted with a 32-character XOR [4]. The key uses the alphabet
[a-f0-9]{32}, which resembles MD5 in format, but we found no additional meaning behind it.• Persistence in the system is achieved via the registry [5]. The stage will execute the next time the user logs into the system.
The GitHub account is active and has been uploading malware since May 2024. Using XOR, even with a 32-byte key, without a cipher block chaining mode makes executables not so well protected 😁 (the second screenshot shows the blob downloaded by the malicious code). The same picture is observed toward the end of the file, which is also rich in null bytes.
The executable is a miner for the Monero cryptocurrency. As a result of the campaign, the attacker managed to mine 15.7 (not million) rubles 🤑
Be careful in open source — it’s fertile ground for attackers’ activities 😼

#pypi #ti #scs #pyanalysis
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



