Tag: Python Package Index (PyPI)

Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts
News

Malicious PyPI Package Impersonates SymPy Deploys XMRig Miner on Linux Hosts

It has been revealed that a new malicious package in the Python Package Index (PyPI) poses as a well-known symbolic mathematics library in order to infect Linux machines with malicious payloads, such as a bitcoin miner. The package, called sympy-dev, attempts to trick unsuspecting users into believing they are downloading a "development version" of the library by imitating SymPy and copying its project description exactly. Since its initial release on January 17, 2026, it has been downloaded more than 1,100 times. The download count probably indicates that some developers may have been impacted by the malicious effort, even though it is not a trustworthy indicator of the quantity of infections. As of this writing, the package is still accessible for download. On hacked systems, t...
AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns
News

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns

With almost 11,000 downloads on the Python Package Index (PyPI) repository, a new artificial intelligence (AI)-powered penetration testing tool associated with a Chinese corporation has sparked worries that hackers may use it maliciously. Cyberspike is credited with creating the Villager framework, which has been marketed as a red teaming solution for automating testing processes. A user called stupidfish001, a former capture the flag (CTF) player for the Chinese HSCSEC team, published the package to PyPI for the first time in late July 2025. According to Straiker researchers Dan Regalado and Amanda Rousseau, in a report shared with The Hacker News, "Villager's rapid, public availability and automation capabilities create a realistic risk that it will follow the Cobalt Strike trajec...
PyPI now blocks domain resurrection attacks used for hijacking accounts
News

PyPI now blocks domain resurrection attacks used for hijacking accounts

The Python Package Index (PyPI) has added new defenses against domain resurrection attacks, which allow accounts to be hijacked by changing their passwords. The official location for open-source Python packages is PyPI. It is utilized by businesses who work with Python libraries, tools, and frameworks as well as software developers and product maintainers. Email addresses are associated with the accounts of project maintainers who publish software on PyPI. For certain projects, a domain name is linked to the email account. After establishing an email server and requesting a password reset for the account, an attacker can register a domain name that has expired and use it to take over a PyPi project. This raises the possibility of a supply-chain attack in which compromised project...
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
News

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

A malicious package that adds malicious behavior through a dependency that enables it to establish persistence and accomplish code execution has been found by cybersecurity experts in the Python Package Index (PyPI) repository. According to Zscaler ThreatLabz, the program, dubbed termncolor, uses a multi-stage malware operation to actualize its malicious capability through a dependent package called colorinal. Colorinal received 529 downloads, compared to 355 for termncolor. On PyPI, both libraries are no longer accessible. According to researchers Manisha Ramcharan Prajapati and Satyam Singh, this attack may use DLL side-loading to enable decryption, create persistence, and carry out command-and-control (C2) communication, ultimately leading to remote code execution. Following i...
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain
News

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain

The Python Package Index (PyPI) repository's maintainers have warned users of a persistent phishing attempt that aims to divert them to fraudulent PyPI websites. The attack entails sending emails from the email address noreply@pypj[.]org with the subject line "[PyPI] Email verification" (notice that the domain is not "pypi[.]org"). Mike Fiedler, the administrator of PyPI, stated in a post on Monday that this is a phishing attempt that takes advantage of users' faith in PyPI rather than a security breach of PyPI itself. The emails direct users to click on a link to confirm their email address, which takes them to a phishing site that mimics PyPI and is set up to steal their login credentials. However, in a devious turn of events, after the login credentials are entered on the f...
This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions
News

This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions

Researchers studying cybersecurity have found a malicious Python package on the Python Package Index (PyPI) repository that can impersonate well-known libraries in order to steal a victim's Ethereum private keys. The package in question is called set-utils, and it has been downloaded 1,077 times thus far. The official registry no longer offers it for download. The package imitates popular libraries like python-utils (712M+ downloads) and utils (23.5M+ downloads), posing as a straightforward utility for Python sets, according to software supply chain security firm Socket. By tricking gullible developers into installing the tainted program read more about This Malicious PyPI Package Stole Ethereum Private Keys via Polygon RPC Transactions. Get up to date on the latest cybersecur...
PyPI adds project archiving system to stop malicious updates
News

PyPI adds project archiving system to stop malicious updates

Informing users that no changes are anticipated, the Python Package Index (PyPI) has announced the launch of "Project Archival," a new method that enables publishers to archive their projects. To assist users in making informed decisions regarding their dependencies, users will still be able to download the projects from PyPI, but they will be alerted of the maintenance state. Because it is typical in the open-source community for developers to take over developer accounts and push malicious updates to popular but abandoned projects, the new functionality aims to strengthen supply-chain security read more about PyPI adds project archiving system to stop malicious updates. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough...
Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts
News

Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts

According to recent findings from Fortinet FortiGuard Labs, cybersecurity experts have identified two malicious packages that were submitted to the Python Package Index (PyPI) repository and had the ability to exfiltrate private data from infected servers. Before being removed, the packages, called Zebo and Cometlogger, received 118 and 164 downloads, respectively. The United States, China, Russia, and India accounted for the majority of these downloads, according to ClickPy figures. According to security researcher Jenna Wang, Zebo is a typical example of malware, with features intended for surveillance, data exfiltration, and unauthorized control. She added that cometlogger also exhibits indicators of malicious activity read more about Researchers Uncover PyPI Packages Stealing Ke...
PyPI Attack ChatGPT Claude Impersonators Deliver JarkaStealer via Python Libraries
News

PyPI Attack ChatGPT Claude Impersonators Deliver JarkaStealer via Python Libraries

Two malicious programs that were posted to the Python Package Index (PyPI) repository were found by cybersecurity experts to deploy an information stealer known as JarkaStealer. The packages mimicked well-known artificial intelligence (AI) models such as OpenAI ChatGPT and Anthropic Claude. A person called "Xeroline" published the programs, which were named gptplus and claudeai-eng, in November 2023. They received 1,748 and 1,826 downloads, respectively. PyPI no longer offers the ability to download either library. One author uploaded the malicious packages to the repository, and according to a report by Kaspersky, the only differences between them were in their names and descriptions read more about PyPI Attack ChatGPT Claude Impersonators Deliver JarkaStealer via Python Libraries....
Hackers Target Python Developers with Fake “Crytic-Compilers” Package on PyPI
News

Hackers Target Python Developers with Fake “Crytic-Compilers” Package on PyPI

A malicious Python package that was posted to the Python Package Index (PyPI) repository with the intention of delivering the information stealer Lumma (also known as LummaC2) has been found by cybersecurity researchers. The package in question is called crytic-compilers, which is a misspelling of the actual crytic-compile library. Before PyPI maintainers removed the fraudulent package, it had been downloaded 441 times. According to Sonatype security researcher Ax Sharma, "the counterfeit library is interesting in that it aligns its version numbers with the real library, in addition to being named after the legitimate Python utility, 'crytic-compile." The fake "crytic-compilers" version starts at 0.3.11 and ends there, giving the impression that this is a newer version of the com...