Malicious Python packages were submitted to the PyPI repository by threat actors, who then advertised them on the StackExchange online Q&A forum.
“spl-types” is the name of the packages. “sol-structs,” “raydium,” “sol-instruct,” and “raydium-sdk” and install programs that take use of the browser, messaging services (Telegram, Signal, Session), and cryptocurrency wallet information (Exodus, Electrum, Monero) to steal private information.
In addition to taking screenshots and exfiltrating files containing particular keywords, the info-stealing software also transmits all of the collected data to a Telegram channel.
According to researchers at Checkmarx, an application security testing business, the packages were added to PyPI on June 25 but the malicious component was included in an update on July 3 read more about StackExchange abused to spread malicious PyPi packages as answers.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
