Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Coinbase says that customer’s personal information was stolen in a data breach

Digital Transformation of Fitness: How AI and TwinH are Revolutionizing Physical Exercise

Compliance-only pen test? It’s time to change your approach

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Malicious PYPI package stole cloud tokens – 14,100 downloads before deleting
Identity

Malicious PYPI package stole cloud tokens – 14,100 downloads before deleting

userBy userMarch 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 15, 2025Ravi Lakshmanan Malware/Supply Chain Security

Malicious Pypi Packages

Cybersecurity researchers have fake libraries that disguise themselves as “time” related utilities for malicious campaigns targeting users of Python Package Index (PYPI) repository, but have hidden features to steal sensitive data, such as cloud access tokens.

Software supply chain security company ReverSinglabs said it has discovered a total of 20 sets of packages. The package has been downloaded cumulatively over 14,100 times –

Snapshot-Photo (2,448 downloads) Time Check Server (316 downloads) Time Check Server – Get (178 downloads) Time Server Analysis (144 downloads) Time Server Analyzer (74 downloads) Time Server Test (155 downloads) Download (151 downloads) (151 downloads) (5,496 downloads) Acloud-Clients (198 downloads) Acloud-Client-USES (294 downloads) Alicloud-Client (622 Downloads) Alicloud-Client-SDK (206 download) AMZCLIENTS-SDK (100 download) AWSCLOUD-CLIENTS-CORE (206 download) download) tclients-sdk (173 download) tcloud-python-sdks (98 download) tcloud-python-test (793 download)

The first set relates to the packages used to upload data to the threat actor’s infrastructure, while the second cluster consists of packages that implement cloud client functionality in several services, such as Alibaba Cloud, Amazon Web Services, and Tencent Cloud.

Cybersecurity

But they also use “time” related packages to remove cloud secrets. All identified packages have already been removed from Pypi at the time of writing.

Further analysis revealed that three packages, Acloud-Client, Enumer-IAM, and Tcloud-Python-Test, are listed as dependencies for a relatively popular Github project named AccessKey_tools, which have been forked 42 times and launched 519 times.

Malicious Pypi Packages

A source code commit was created on November 8, 2023 to reference Tcloud-Python-Test, indicating that the package can be downloaded in Pypi ever since. For each Pepy.tech statistics, the package has been downloaded 793 times so far.

This disclosure comes as Fortinet Fortiguard Labs said it discovered thousands of packages across Pypi and NPM. Some of them are known to include suspicious installation scripts designed to deploy malicious code during installation and communicate with external servers.

“Suspicious URLs are a key indicator of potentially malicious packages as they are used to download additional payloads, establish communication with command and control (C&C) servers, and are often used to control infected systems to attackers,” says Jenna Wang.

“In the 974 packages, such URLs are linked to the risk of data stripping, malware downloading, and other malicious actions. It is important to scrutinize and monitor external URLs of package dependencies to prevent exploitation.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTrump’s Columbia University arrests international university students for worrying
Next Article Russian captain of North Sea ship collision charged with manslaughter | Shipment News
user
  • Website

Related Posts

Compliance-only pen test? It’s time to change your approach

May 15, 2025

Malicious NPM packages leverage Unicode Steganography, Google Calendar as C2 Dropper

May 15, 2025

New Chrome vulnerability enables cross-origin data leaks via loader referrer policy

May 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Coinbase says that customer’s personal information was stolen in a data breach

Digital Transformation of Fitness: How AI and TwinH are Revolutionizing Physical Exercise

Compliance-only pen test? It’s time to change your approach

Leeds host crimbuk burns innovation and investment in the north

Trending Posts

“One Long Nakba”: Palestinians celebrate 77 years since Israel’s mass expulsion | Israeli-Palestinian conflict news

May 15, 2025

New Zealand discusses suspension of protesters from Maori lawmakers | Indigenous Rights News

May 15, 2025

Amidst rising tensions, we meet Trump next week in South Africa Ramaphosa | Political News

May 15, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Digital Transformation of Fitness: How AI and TwinH are Revolutionizing Physical Exercise

sportsbet.io releases 1 million USDT gifts to mark the Champions League finale

AI replaces humans: Klarna replaces 700 employees with AI, slashing the workforce by 40%

Voltra emerges from stealth for $1.8 million to launch “Charge,” a stripe-like API for EV chargers and microgrids.

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.