Two new malicious packages that are intended to install the remote access trojan SilentSync on Windows PCs have been found by cybersecurity experts in the Python Package Index (PyPI) repository.
Screen capture, file exfiltration, and remote command execution are all possible using SilentSync, according to Manisha Ramcharan Prajapati and Satyam Singh of Zscaler ThreatLabz. Additionally, SilentSync retrieves browser information from Chrome, Brave, Edge, and Firefox, including login credentials, history, autofill information, and cookies.
The packages listed below can no longer be downloaded from PyPI. CondeTGAPIS is the user that uploaded both of them.
- sisaws (201 Downloads)
- secmeasure (627 Downloads)
According to Zscaler, the package sisaws imitates the functionality of the authentic Python program sisa, which is connected to Sistema Integrado de Información Sanitaria Argentino (SISA), Argentina’s national health information system.
Nevertheless, the initialization script (init.py) contains a function named “gen_token()” that is part of the library and serves as a downloader read more about SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
