Crypto-stealing malware discovered in Python Package Index — Checkmarx



The Hidden Threat: How Malware Infiltrated the Python Package Index

A Sneaky Cyber Menace

Security experts at Checkmarx have recently raised the alarm a couple of sneaky malware strain lurking throughout the Python Package Index (PyPI). This platform, beloved by Python developers for code sharing and downloading, became a hunting ground for a cunning piece of malware designed to swipe private keys, mnemonic phrases, and other sensitive user data.



The Disguised Danger

The folks at Checkmarx discovered that this malware was slyly uploaded by a sketchy user into multiple software packages. These packages impersonated popular wallet applications like MetaMask, Atomic, TronLink, and Ronin, amongst others. By cleverly embedding itself in parts of the software that looked harmless at first glance, the malware managed to evade detection.

The first signs of trouble appeared back in March 2024 when an identical malicious software package infiltrated the PyPI. The quick-thinking team at Checkmarx managed to pinpoint the threat, prompting the platform to halt recent projects and account creations until the issue was resolved. But, like a nasty penny, the malware returned in October, reportedly getting over 3,700 downloads since.



An Ongoing Battle

Despite the swift motion by Checkmarx and PyPI to tackle this threat, the malware scene is evolving rapidly. McAfee Labs uncovered a classy piece of malware in September that targeted Android smartphones, able to lifting private keys from images stored on the device. This malware spread through links in text messages, fooling users into downloading what they thought were legitimate apps.

See also  Group-IBAPT Lazarus: Eager Crypto Beavers, Video calls and GamesExplore the growing threats posed by the Lazarus Group's financially-driven campaign against developers. We will examine their recent Python scripts..4 sept. 2024

AI: The New Tool for Cybercriminals

Cybersecurity specialists at Hewlett-Packard’s Wolf Security team have highlighted a troubling trend: cybercriminals are leveraging artificial intelligence to craft malware. This development lowers the barrier for creating these malicious programs, making them more accessible to would-be hackers.

The Digital Plague Continues

In a recent October incident, over 28,000 users fell victim to malware masquerading as productivity and gaming software. Fortunately, the damage was limited to a $6,000 loss, but it surely serves as a stark reminder of the continuing cyber threats we face.

Related: Symbiotic X Hacked, Malware is Infecting SVG Files: Crypto-Sec

Magazine: 2 Auditors Miss $27M Penpie Flaw, Pythia’s ‘Claim Rewards’ Bug: Crypto-Sec

Image Credit: cointelegraph.com

Hot Topics

Related Articles

bitcoin
Bitcoin (BTC) $ 117,413.46
ethereum
Ethereum (ETH) $ 3,746.87
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 783.87
xrp
XRP (XRP) $ 3.16
cardano
Cardano (ADA) $ 0.819646
usd-coin
USDC (USDC) $ 1.00
matic-network
Polygon (MATIC) $ 0.233684
binance-usd
BUSD (BUSD) $ 0.998669
dogecoin
Dogecoin (DOGE) $ 0.237735
okb
OKB (OKB) $ 48.05
polkadot
Polkadot (DOT) $ 4.10
shiba-inu
Shiba Inu (SHIB) $ 0.000014
tron
TRON (TRX) $ 0.319098
uniswap
Uniswap (UNI) $ 10.43
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 117,443.47
dai
Dai (DAI) $ 1.00
litecoin
Litecoin (LTC) $ 113.37
staked-ether
Lido Staked Ether (STETH) $ 3,740.41
solana
Solana (SOL) $ 186.68
avalanche-2
Avalanche (AVAX) $ 24.17
chainlink
Chainlink (LINK) $ 18.25
cosmos
Cosmos Hub (ATOM) $ 4.68
the-open-network
Toncoin (TON) $ 3.31
ethereum-classic
Ethereum Classic (ETC) $ 23.05
leo-token
LEO Token (LEO) $ 8.98
filecoin
Filecoin (FIL) $ 2.64
bitcoin-cash
Bitcoin Cash (BCH) $ 553.77
monero
Monero (XMR) $ 327.49