Carding tool abusing WooCommerce API downloaded 34K times on PyPI
Since its discovery, the malicious PyPi package 'disgrasya' has been downloaded more than 34,000 times from the open-source package marketplace. It exploits authentic WooCommerce stores to validate payment cards that have been stolen.
Carding players must assess hundreds of stolen cards from dark web dumps and leaked databases to ascertain their value and potential for exploitation. The script especially targeted WooCommerce stores that used the CyberSource payment gateway to authenticate cards.
The package's huge download numbers demonstrate the extent of usage for these kinds of nefarious operations, even though it has been removed from PyPI.
According to a report by Socket researchers, Disgrasya made no effort to seem authentic, in contrast to conventional supply chain hacks t...

