Malicious PyPI packages hijack dev devices to mine cryptocurrency



Sneaky Malicious Packages Turn PyPI right into a Cryptomining Haven



Malicious Code Found in Popular Python Repository

This week, a handful of nasty packages were busted within the PyPI repository, a preferred hub for Python projects, after they were found turning developers’ computers into unwitting cryptomining machines. Yikes!

These rogue packages were all released by the identical user account, cleverly disguising themselves with names eerily much like legitimate Python projects. This trickery led to 1000’s of unsuspecting downloads.

The Bash Script Culprit

In April, a sneaky total of six malicious packages wormed their way into the Python Package Index (PyPI):

  • maratlib
  • maratlib1
  • matplatlib-plus
  • mllearnlib
  • mplatlib
  • learninglib

These packages were all linked to a user often called “nedog123,” and plenty of of them had names that were merely misspelled versions of the well-known matplotlib plotting software.

Security researcher Ax Sharma from Sonatype, an organization specializing in DevOps automation, took a deep dive into one in all these packages, “maratlib,” in a blog post. He found it was used as a dependency by the opposite malicious packages.

What’s within the Code?

Sharma discovered that every package contained harmful code throughout the setup.py file, which is a construct script executed in the course of the package installation process.

While digging into this package, Sharma found that it tried to download a Bash script (aza2.sh) from a now-defunct GitHub repository. Using open-source intelligence, he traced the creator’s aliases on GitHub and uncovered that the script was meant to run a cryptominer called “Ubqminer” on the infected machine.



Ubqminer downloaded by bad PyPI package

Sharma also noted that the malware creator swapped out the default Kryptex wallet address with their very own, allowing them to mine Ubiq cryptocurrency (UBQ) for themselves.

See also  JFrog Sounds Alarm on Crypto-Stealing Python Package

In one other twist, some scripts included a distinct cryptomining tool that utilizes GPU power, the open-source T-Rex.

PyPI package downloads T-Rex cryptomining program

The Bigger Picture

Attacks on open-source code repositories like PyPI, NPM for NodeJS, and RubyGems have gotten all too common [1, 2, 3]. Even when detection happens early, with only just a few downloads, the chance stays significant as developers might unknowingly incorporate these malicious packages into widely-used projects.

Luckily, on this case, the six malicious packages were flagged by Sonatype’s automated malware detection tool, Release Integrity, after scanning the PyPI repository. By the time they were caught, the packages had racked up nearly 5,000 downloads since April, with “maratlib” being essentially the most downloaded at 2,371 times.

See also  Cryptocurrency Live News & Updates : Eyenovia Stock Soars Over 65% After Financing News

Wiz

Want to remain ahead of emerging threats? Real-time containment is your answer. Discover how cloud detection and response (CDR) equips security teams to tackle threats effectively on this no-nonsense guide.

Get the Guide

Image Credit: www.bleepingcomputer.com

Hot Topics

Related Articles

bitcoin
Bitcoin (BTC) $ 118,554.76
ethereum
Ethereum (ETH) $ 3,862.46
tether
Tether (USDT) $ 1.00
bnb
BNB (BNB) $ 809.90
xrp
XRP (XRP) $ 3.17
cardano
Cardano (ADA) $ 0.786349
usd-coin
USDC (USDC) $ 0.999981
matic-network
Polygon (MATIC) $ 0.221474
binance-usd
BUSD (BUSD) $ 0.993397
dogecoin
Dogecoin (DOGE) $ 0.224683
okb
OKB (OKB) $ 47.94
polkadot
Polkadot (DOT) $ 3.89
shiba-inu
Shiba Inu (SHIB) $ 0.000013
tron
TRON (TRX) $ 0.325684
uniswap
Uniswap (UNI) $ 10.17
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 118,484.75
dai
Dai (DAI) $ 1.00
litecoin
Litecoin (LTC) $ 111.06
staked-ether
Lido Staked Ether (STETH) $ 3,858.81
solana
Solana (SOL) $ 181.87
avalanche-2
Avalanche (AVAX) $ 23.98
chainlink
Chainlink (LINK) $ 18.17
cosmos
Cosmos Hub (ATOM) $ 4.51
the-open-network
Toncoin (TON) $ 3.55
ethereum-classic
Ethereum Classic (ETC) $ 21.81
leo-token
LEO Token (LEO) $ 8.93
filecoin
Filecoin (FIL) $ 2.54
bitcoin-cash
Bitcoin Cash (BCH) $ 586.39
monero
Monero (XMR) $ 314.48