Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The PyPI malware package targets macOS to steal Google Cloud credentials
Global Security

The PyPI malware package targets macOS to steal Google Cloud credentials

AdminBy AdminJuly 27, 2024No Comments2 Mins Read
Malicious PyPI Package
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 27, 2024Information hallCyber ​​Security / Cloud Security

The malicious PyPI package

Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that targets Apple macOS systems to steal Google Cloud user credentials from a narrow pool of victims.

A package called “lr-utils-lib” attracted a total 59 downloads before it was taken down. It was uploaded to the registry in early June 2024.

“The malware uses a list of predefined hashes to target specific macOS machines and attempts to collect Google Cloud authentication data,” Checkmarx researcher Yehuda Gelb. said in Friday’s report. “Collected credentials are sent to a remote server.”

Cyber ​​security

An important aspect of the package is that it first checks if it has been installed on a macOS system before proceeding to compare the system’s Universally Unique Identifier (UUID) with a hard-coded list of 64 hashes.

If the compromised machine is among those specified in the predefined set, it tries to access two files, namely application_default_credentials.json and credentials.db, located in the ~/.config/gcloud directory, which contain Google Cloud credentials.

The malicious PyPI package

The resulting information is then transmitted via HTTP to the remote server “europe-west2-workload-422915(.)cloudfunctions(.)net”.

Checkmarx said it also found a fake LinkedIn profile with the name “Lucid Zenith” matching the owner of the package and falsely claiming to be the CEO of Apex Companies, suggesting a possible social engineering element to the attack.

Who exactly is behind the company is still unknown. However, this comes more than two months after cyber security company Phylum opened details another supply chain attack involving a Python package called “requests-darwin-lite”, which was also found to have released its malware after inspecting the UUID of the macOS host.

These campaigns are a sign that threat actors have prior knowledge of the macOS systems they want to infiltrate, and are working hard to ensure that malicious packages are only distributed to those specific machines.

It also speaks to the tactics attackers use to distribute similar packages to trick developers into including them in their applications.

“While it is unclear whether this attack targeted individuals or businesses, such attacks can have a significant impact on businesses,” Gelb said. “While the initial compromise typically occurs on an individual developer’s machine, the implications for businesses can be significant.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.