Friday, August 19, 2022

Malicious PyPi packages turn Discord into password-stealing malware

Python developers are under attack once again, with attackers looking to steal Discord account details along with data stored in various browsers

Cybersecurity researchers from Snyk have recently spotted a dozen malicious packages, uploaded to PyPi, the biggest Python code repository out there, with more than 600,000 active users. 

The packages were uploaded almost a month ago, by a threat actor called “scarycoder”. They claim to provide the users with various functionalities, Roblox tools, thread management, and others. Instead, the researchers have found, all the packages do is steal sensitive information.

Stealing passwords 

Different packages are capable of stealing different things. Some are focused on data stored in browsers such as Google Chrome, Chromium, Microsoft Edge, Firefox, and Opera. The data includes stored passwords, browser history, cookies, and search history. Others are installing backdoors directly into the Discord client, stealing authentication tokens, Nitro status, billing information, and credit card data.

One of the malicious programs attacks Roblox, it was further said, stealing account cookies, user IDs, Robux balance, and Premium status. 

PyPi’s administrators are relatively slow to respond, the publication states, adding that it’s probably not due to negligence, but rather due to the fact that the entire project is run by a handful of volunteers who simply can’t keep up with a tidal wave of malware uploads. 

Still, the slow response means many of Python developers will remain exposed to various viruses, malware, and other forms of attacks.

Experts from Spectralops recently found 10 malicious packages on the PyPi platform. All of these were given names that are almost identical to the names of legitimate packages in order to dupe developers into downloading, and adopting, the tainted ones. The practice is called typosquatting, and it’s quite a common occurrence in the developer community.

Via: BleepingComputer



from TechRadar - All the latest technology news https://ift.tt/3F945Uo

No comments:

Post a Comment

Forget about Wi-Fi, your own private 5G network could be the answer to your connection woes — here's how to set one up for much cheaper than you think

Private 5G networks, where individuals or companies set up their own cellular connections, could potentially provide a viable alternative t...