Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hackers distribute malicious Python packages through a popular developer Q&A platform
Global Security

Hackers distribute malicious Python packages through a popular developer Q&A platform

AdminBy AdminAugust 1, 2024No Comments4 Mins Read
Python Packages
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


Python packages

In another sign that threat actors are always looking for new ways to trick users into downloading malware, it emerged that a question-and-answer (Q&A) platform known as Stack Exchange was used to direct unsuspecting developers to fake Python packages capable of drain their cryptocurrency wallets.

“Once installed, this code will execute automatically, triggering a chain of events designed to hack and control the victim’s systems, steal their data and drain their crypto wallets,” Checkmarx researchers Yehuda Gelb and Tzahi Zornstein said in the report shared with The Hacker News.

The campaign, which began on June 25, 2024, specifically singled out cryptocurrency users associated with Raydium and Solana. The list of unauthorized packages detected during this activity is given below –

The packages have been downloaded a total of 2082 times. They are no longer available for download from the Python Package Index (PyPI) repository.

Cyber ​​security

The malware hidden in the package served as a full-fledged information stealer, scattering a wide web of data, including web browser passwords, cookies and credit card details, cryptocurrency wallets and information related to messaging apps such as Telegram, Signal and Session .

It also has the ability to take system screenshots and search for files containing GitHub recovery codes and BitLocker keys. The collected information was then compressed and sent to two different Telegram bots maintained by the criminals.

Separately, the backdoor component present in the malware provided the attacker with permanent remote access to the victim’s machines, allowing for possible future exploits and long-term compromise.

The attack chain spans several steps, with the “raydium” package listing “spl-types” as a dependency in an attempt to hide the malicious behavior and give users the impression that it was legitimate.

A notable aspect of the campaign is to use Stack Exchange as a vector for adoption by posting supposedly helpful answers with links to the package in question on developer questions related to performing swap transactions in Raydium using Python.

Python packages

“By choosing a high-visibility thread — racking up thousands of views — the attacker maximized his potential reach,” the researchers said, adding that this was done to “give credibility to this package and ensure its widespread distribution.”

Although the answer no longer exists on Stack Exchange, The Hacker News found references to “raydium” elsewhere an unanswered question posted on Q&A on July 9, 2024: “I’ve been struggling at night to replace a solana mesh running on python 3.10.2, solana, solder and raydium installed, but I can’t get it to work” – the user said.

Links to “raydium-sdk” are also there surfaced in a post titled “How to Buy and Sell Raydium Tokens Using Python: A Solana Step-by-Step Guide” shared by SolanaScribe on the social media platform Medium on Jun 29, 2024.

It is currently unclear when the packages were removed from PyPI, as two other users responded to a Medium post asking the author for help installing “raydium-sdk” as recently as six days ago. Checkmarks told The Hacker News that the message was not the work of the threat author.

This is not the first time criminals have resorted to this method of spreading malware. Earlier in May, Sonatype revealed how a package called pytoileur was promoted through another Q&A service called Stack Overflow to facilitate cryptocurrency theft.

If anything, this event is proof that attackers are exploiting the trust in these community-driven platforms to promote malware, leading to large-scale supply chain attacks.

“One compromised developer can inadvertently introduce vulnerabilities into an entire company’s software ecosystem, potentially affecting the entire corporate network,” the researchers said. “This attack serves as a wake-up call for both individuals and organizations to rethink their security strategies.”

The development comes after Fortinet FortiGuard Labs detailed a malicious PyPI package called zlibxjson that contains features to steal sensitive information such as Discord tokens, cookies stored in Google Chrome, Mozilla Firefox, Brave and Opera, and saved passwords from browsers. The library attracted a total 602 downloads before it was pulled from PyPI.

“These actions can lead to unauthorized access to user accounts and theft of personal data, clearly classifying the software as malicious,” security researcher Jenna Wang. said.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Operation malicious network supply software gets to NPM and Pypi ecosystems, focusing on millions worldwide

June 8, 2025

Extension of the malicious browser has infected 722 users across Latin America since the beginning of 2025

June 8, 2025

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.