Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Harmful
Global Security

Harmful

AdminBy AdminFebruary 26, 2025No Comments3 Mins Read
Deezer Music Downloads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 26, 2025Red LakshmananMalicious software / cryptocurrency

Deezer Music Downloads

Cybersecurity researchers have indicated the Python Python Package (Pypi) malicious Python library, which facilitates an unauthorized download of music from Music Streaming Service Deezer.

In this package – Automslc, which is now loaded more than 104,000 times. For the first time published in May 2019, this Remains are available on Pypi from writing.

“Although the Automslc that was downloaded More than 100,000 times supposed to offer musical automation and search metadata, it is hidden bypassing Deezer’s access restrictions, built up hard credentials and talking to the external team server and control (C2), “Socket Kirill Boychenko Research – Note In a report published today.

Cybersecurity

In particular, the package is designed to enter the French streaming platform with custom and hard credentials, collect metadata related to track, and download full audio files in violation of API Deezer.

The package also periodically talks to a remote server located on “54.39.49 (.) 17: 8031” to provide updates of the load state, which thus gives the centralized control over the coordinated music of the pirated operation.

Otherwise, AutomslC effectively turns packages to the illegal network to facilitate the download of mass music into an unauthorized order. IP -Drass is associated with a domain called “Automusic (.) Win”, which is said to be used by an actor threatening to control the distributed loading operation.

Deezer Music Downloads

“API Deezer conditions prohibit local or autonomous repository of full sound, but by loading and deciphering whole tracks, Automslc bypasses this restriction, potentially subjecting the risk of legal consequences,” said Boychenko.

Disclosure occurs when the software chain safety company talked in detail about the NPM Rogue package called @ton-wallet/CREATE, which was found theft melmonic phrases From non -suspicious users and developers in the Ton ecosystem, simultaneously pretending to be a legal package @ton/ton.

The package, first published In the NPM register in August 2024, attracted 584 boot Today. It remains available for download.

Cybersecurity

The malicious functionality laid into the library is able to retrieve a variable procedure. The information is transmitted from the bot bot bot -controlled attacker.

“This attack creates serious safety risks of supply chain, focusing on developers and users who integrate into their TON TON applications – Note. “Regular dependence audit and automated scan tools should be used to detect abnormal or malicious behavior in other packages before they are integrated into production conditions.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.