PyPI crypto-stealer targets Windows users, revives malware campaign



Pytoileur: A Sneaky Threat in Disguise

Recently, a PyPI package named “pytoileur” was flagged by Sonatype’s automated malware detection systems. This package, which was tracked as sonatype-2024-1783, was downloaded 264 times before it was removed from the PyPI platform. It masqueraded as a “Cool package” and falsely claimed to be an “API Management tool written in Python.” However, its true nature was far from benign. The package was designed to exploit users by disguising itself as a legitimate tool, aiming to trick users into downloading and installing it.



Interestingly, “Pytoileur” was the only package published by a PyPI user named “PhilipsPY,” who joined the platform on May 25, 2024. The package’s “setup.py” file appeared clean at first glance, but upon closer inspection, it was clear that something was amiss. Sonatype’s security researcher, Jeff Thornhill, spotted unusual whitespace in the code, cleverly used to hide a base64-encoded payload, making it easy to overlook without scrolling to the right.

The payload was designed to download a malicious executable from an external server, targeting Windows users. The binary, “Runtime.exe,” was executed using Windows PowerShell and VBScript commands, further compromising the system by achieving persistence and deploying anti-detection measures.



The package also deployed additional suspicious executables, manipulated Windows registry settings, and contained components previously identified as spyware. One binary, “main.exe,” was equipped with information-stealing and crypto-jacking capabilities. It
Image Credit: www.sonatype.com

See also  Ultralytics AI Library with 60M Downloads Compromised for Cryptomining

Hot Topics

Related Articles

bitcoin
Bitcoin (BTC) $ 118,270.69
ethereum
Ethereum (ETH) $ 3,771.49
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 795.17
xrp
XRP (XRP) $ 3.20
cardano
Cardano (ADA) $ 0.828476
usd-coin
USDC (USDC) $ 1.00
matic-network
Polygon (MATIC) $ 0.236822
binance-usd
BUSD (BUSD) $ 0.997766
dogecoin
Dogecoin (DOGE) $ 0.238938
okb
OKB (OKB) $ 48.25
polkadot
Polkadot (DOT) $ 4.18
shiba-inu
Shiba Inu (SHIB) $ 0.000014
tron
TRON (TRX) $ 0.320619
uniswap
Uniswap (UNI) $ 10.60
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 118,154.66
dai
Dai (DAI) $ 1.00
litecoin
Litecoin (LTC) $ 114.83
staked-ether
Lido Staked Ether (STETH) $ 3,767.73
solana
Solana (SOL) $ 186.57
avalanche-2
Avalanche (AVAX) $ 25.00
chainlink
Chainlink (LINK) $ 18.68
cosmos
Cosmos Hub (ATOM) $ 4.80
the-open-network
Toncoin (TON) $ 3.32
ethereum-classic
Ethereum Classic (ETC) $ 23.09
leo-token
LEO Token (LEO) $ 8.99
filecoin
Filecoin (FIL) $ 2.69
bitcoin-cash
Bitcoin Cash (BCH) $ 570.21
monero
Monero (XMR) $ 322.17