Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo

A malicious Python package that appears to be a spin-off of the popular requests library has been discovered by cybersecurity experts to be hiding a Golang version of the Sliver command-and-control (C2) framework behind a PNG image of the project’s logo.

Requests-darwin-lite is the package utilizing this steganographic technique; it was downloaded 417 times before it was removed from the Python Package Index (PyPI) repository.

Software supply chain security firm Phylum reported that requests-darwin-lite looked to be a fork of the widely used requests package with a few significant modifications, most notably the presence of a malicious Go binary bundled into a sizable version of the genuine requests side-bar PNG logo.

The modifications are made to the setup.py file in the package read more Malicious Python Package Hides Sliver C2 Framework in Fake Requests Library Logo.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *