Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Malicious Pypi Packages stole cloud tokens – more than 14 100 boot before removal
Global Security

Malicious Pypi Packages stole cloud tokens – more than 14 100 boot before removal

AdminBy AdminMarch 15, 2025No Comments3 Mins Read
Malicious PyPI Packages
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 15, 2025Red Lakshmanan Safety malicious programs / chains of supply

Malicious Pypi packages

Cybersecurity researchers have warned of a malicious campaign aimed at Python Package (Pypi) repository users disguised as “time”, but the withdrawal of hidden functionality to steal sensitive data such as cloud access tokens.

Software Price Chain Safety Firm Reversinglabs – Note He discovered two sets of packages totaling 20 of them. The packages were cumulatively loaded more than 14 100 times –

  • Snapshot-Photo (2448 boot)
  • Check time (316 boot)
  • Check time-server (178 boot)
  • Analysis of time-server (144 boot)
  • Temporary server analyzer (74 boot)
  • Time-server test (155 boot)
  • Check time (151 downloads)
  • ACLIENT-SDK (120 boot)
  • ACloud-Client (5496 boot)
  • ACLOUD-CLIENS (198 boot)
  • ACLOUD-CLIENT-USE (294 boot)
  • ALICLOUD-CLIENT (622 Downloads)
  • ALICLOUD-CLIENT-SDK (206 boot)
  • AMZCLIENTS-SDK (100 boot)
  • Awscloud-Clients-Core (206 boot)
  • Accounting Python-SDK (1155 boot)
  • List-Aim (1.254 boot)
  • TCLIENS-SDK (173 boot)
  • TCLOUD-PYTHON-DDKS (98 Boot)
  • TCloud-Python-Test (793 boot)

While the first set refers to the packages used to download the actor infrastructure, the second cluster consists of packages that implement client clients’ functionality for multiple services such as Alibaba Cloud, Amazon Web Services and Tencent Cloud.

Cybersecurity

But they also use packages associated with “sometimes” to exfiltrate cloud secrets. All revealed packages have already been removed from Pypi from writing.

Further analysis showed that three packages, ACloud-Client. The list is unnamedand TCLOUD-PYTHON-TESTwas entered as a dependence on a relatively popular GitHub project named Accesskey_tools It was split 42 times and started 519 times.

Malicious Pypi packages

Based on the source code, which refers to TCLOUD-PYTHON-TEST, was made on November 8, 2023, which indicates that the package has been available to download on Pypi since. The package was loaded 793 times today, according to Pepy.tech statistics.

The disclosure of information occurs when Fortinet Fortiguard Labs said it revealed thousands of Pypi and NPM packages, some of which were found built -in suspicious institutions designed to place malicious code while installing or communicating with external servers.

“Suspicious URL is a key indicator of potentially malicious packages as they are often used to download additional useful loads or communication with command servers (C&C) – Note.

“In 974 packages, such URLs are associated with the risk of data expressing, further loading malware and other malware. It is important to study and control external URLs, depending on the packages to prevent operation.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.