Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Malicious Pypi Packages stole cloud tokens – more than 14 100 boot before removal
Global Security

Malicious Pypi Packages stole cloud tokens – more than 14 100 boot before removal

AdminBy AdminMarch 15, 2025No Comments3 Mins Read
Malicious PyPI Packages
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 15, 2025Red Lakshmanan Safety malicious programs / chains of supply

Malicious Pypi packages

Cybersecurity researchers have warned of a malicious campaign aimed at Python Package (Pypi) repository users disguised as “time”, but the withdrawal of hidden functionality to steal sensitive data such as cloud access tokens.

Software Price Chain Safety Firm Reversinglabs – Note He discovered two sets of packages totaling 20 of them. The packages were cumulatively loaded more than 14 100 times –

  • Snapshot-Photo (2448 boot)
  • Check time (316 boot)
  • Check time-server (178 boot)
  • Analysis of time-server (144 boot)
  • Temporary server analyzer (74 boot)
  • Time-server test (155 boot)
  • Check time (151 downloads)
  • ACLIENT-SDK (120 boot)
  • ACloud-Client (5496 boot)
  • ACLOUD-CLIENS (198 boot)
  • ACLOUD-CLIENT-USE (294 boot)
  • ALICLOUD-CLIENT (622 Downloads)
  • ALICLOUD-CLIENT-SDK (206 boot)
  • AMZCLIENTS-SDK (100 boot)
  • Awscloud-Clients-Core (206 boot)
  • Accounting Python-SDK (1155 boot)
  • List-Aim (1.254 boot)
  • TCLIENS-SDK (173 boot)
  • TCLOUD-PYTHON-DDKS (98 Boot)
  • TCloud-Python-Test (793 boot)

While the first set refers to the packages used to download the actor infrastructure, the second cluster consists of packages that implement client clients’ functionality for multiple services such as Alibaba Cloud, Amazon Web Services and Tencent Cloud.

Cybersecurity

But they also use packages associated with “sometimes” to exfiltrate cloud secrets. All revealed packages have already been removed from Pypi from writing.

Further analysis showed that three packages, ACloud-Client. The list is unnamedand TCLOUD-PYTHON-TESTwas entered as a dependence on a relatively popular GitHub project named Accesskey_tools It was split 42 times and started 519 times.

Malicious Pypi packages

Based on the source code, which refers to TCLOUD-PYTHON-TEST, was made on November 8, 2023, which indicates that the package has been available to download on Pypi since. The package was loaded 793 times today, according to Pepy.tech statistics.

The disclosure of information occurs when Fortinet Fortiguard Labs said it revealed thousands of Pypi and NPM packages, some of which were found built -in suspicious institutions designed to place malicious code while installing or communicating with external servers.

“Suspicious URL is a key indicator of potentially malicious packages as they are often used to download additional useful loads or communication with command servers (C&C) – Note.

“In 974 packages, such URLs are associated with the risk of data expressing, further loading malware and other malware. It is important to study and control external URLs, depending on the packages to prevent operation.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025

Mirror aims Japan and Taiwan with Roysingmouse and upgraded malicious program

May 8, 2025

Only security tools do not protect you – control efficiency makes

May 8, 2025

Russian hackers using Flackfix Fake CAPTCHA to deploy new malware LostKeys

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025

Mirror aims Japan and Taiwan with Roysingmouse and upgraded malicious program

May 8, 2025

Only security tools do not protect you – control efficiency makes

May 8, 2025

Russian hackers using Flackfix Fake CAPTCHA to deploy new malware LostKeys

May 8, 2025

Cisco Patches Cve-2025-20188 (10.0 CVSS) in iOS XE, which allows root feat via JWT

May 8, 2025

Ottokit WordPress plugin with 100K+ Instals Hit Gratoits, focused on several disadvantages

May 7, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.