[ << ALL_FEED ]

The city celebrates, the mafia wakes up

More in General

The city celebrates, the mafia wakes up 🥰

Between January 1 and 11, approximately 180 malicious packages were removed from the NPM ecosystem, and 16 from PyPI. Attackers on PyPI are lazy. We’ll tell you about a little New Year’s magic within a single PyPI package.

On January 4, user ambertransit published a project called aiihttp, whose name mimics the http client aiohttp.

The code begins with simple obfuscation:

import base64

exec(base64.b64decode('aW1wb3J0IGl...')Code language: Python (python)


The logic hidden behind base64 is shown in the first screenshot. Key points:

• The package gentlemanly helps the developer who made a typo: it deletes itself, installs aiohttp [item 1 in screenshot 1], then reloads the module if it was already imported [2].

• The next stage is hosted on GitHub [3]. However, it’s not that simple — it’s encrypted with a 32-character XOR [4]. The key uses the alphabet [a-f0-9]{32}, which resembles MD5 in format, but we found no additional meaning behind it.

• Persistence in the system is achieved via the registry [5]. The stage will execute the next time the user logs into the system.

The GitHub account is active and has been uploading malware since May 2024. Using XOR, even with a 32-byte key, without a cipher block chaining mode makes executables not so well protected 😁 (the second screenshot shows the blob downloaded by the malicious code). The same picture is observed toward the end of the file, which is also rich in null bytes.

The executable is a miner for the Monero cryptocurrency. As a result of the campaign, the attacker managed to mine 15.7 (not million) rubles 🤑

Be careful in open source — it’s fertile ground for attackers’ activities 😼


#pypi #ti #scs #pyanalysis
@ptescalator

More from ti_author

More from ti_author

More in General