Friday, February 3, 2023
  • Login
No Result
View All Result
Atreju
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3
    • Home – Layout 4
    • Home – Layout 5
  • World
  • News
  • SPORTS
  • Entertainment
  • Politics
  • Italy
  • Technology
No Result
View All Result
Atreju
No Result
View All Result
ADVERTISEMENT
Home Technology

Programmers: look out for these infostealers on the Python Package Index

by Atreju
January 17, 2023
in Technology
0
Magnifying glass enlarging the word
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Three malicious packages carrying infostealers were recently discovered, and subsequently removed, from the PyPI repository.

Researchers from Fortinet found three packages, uploaded between January 7 and 12, by a user named “Lollip0p”. These three are called “colorslib”, “httpslib”, and “libhttps”, and if you’ve used them before, make sure to remove them immediately. 

Usually, cybercriminals looking to compromise Python developer endpoints via PyPI will try typosquatting – giving their malicious packages names almost identical to others belonging to legitimate projects. That way, developers who are either reckless, or in a hurry, might unknowingly use the malicious one, instead of the clean one. 

Stealing browser data

This campaign, however, is different, as these three have unique names. To build trust, the attacker drafted complete descriptions for the packages. While the total download count for these three hardly surpassed 500, it might still prove devastating if it’s a part of a larger supply chain, the publication states.

In all three cases, the attackers are distributing a file called “setup.py” which, after running a PowerShell, tries to download the “Oxyz.exe” executable from the internet. This executable, the researchers are saying, is malicious, and steals browser information. We don’t know exactly what type of information the malware (opens in new tab) is looking to steal, but infostealers usually go for saved passwords, credit card data, cryptocurrency wallets, and other valuable information.

 The report also found that the detection rate for these executables are relatively low (up to 13.5%), meaning the attackers can successfully siphon out data even from endpoints protected by antivirus solutions. 

While the malicious packages have been removed from PyPI already, nothing is stopping the attackers from simply uploading them with a different name, and from a different account. That being said, the best way to protect against this type of supply chain attack is to be particularly careful when downloading code building blocks from repositories. 

Via: BleepingComputer (opens in new tab)

Atreju

Atreju

Next Post
Vodafone Italia top employer per il sesto anno di seguito

Vodafone Italia top employer per il sesto anno di seguito

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

An Seyoung Beats Akane Yamaguchi to Clinch Women's Singles Title, Kunlavut Vitidsarn Emerge Men's Singles Champion

An Seyoung Beats Akane Yamaguchi to Clinch Women’s Singles Title, Kunlavut Vitidsarn Emerge Men’s Singles Champion

2 weeks ago
Best MW2 TAQ-56 loadout for Season 1 Reloaded

Best MW2 TAQ-56 loadout for Season 1 Reloaded

3 weeks ago

Popular News

    Connect with us

    Newsletter

    Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor.
    SUBSCRIBE

    Category

    • Business
    • Entertainment
    • Fashion
    • food
    • Games
    • Gaming
    • Health
    • Italy
    • Lifestyle
    • Movie
    • Music
    • National
    • News
    • Politics
    • Science
    • SPORTS
    • Tech
    • Technology
    • Travel
    • Uncategorized
    • WORLD

    Site Links

    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org

    About Us

    We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

    • About
    • Advertise
    • Careers
    • Contact

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    No Result
    View All Result
    • Home
    • Politics
    • World
    • Business
    • Science
    • National
    • Entertainment
    • Gaming
    • Movie
    • Music
    • Sports
    • Fashion
    • Lifestyle
    • Travel
    • Tech
    • Health
    • Food

    © 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Create New Account!

    Fill the forms below to register

    All fields are required. Log In

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In