Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Livermore Computing: Accelerating excellence in HPC

Strategies for next-gen medical technologies

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Fake Python Spellchecker package on PyPI delivers hidden remote access Trojan
Identity

Fake Python Spellchecker package on PyPI delivers hidden remote access Trojan

userBy userJanuary 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananJanuary 28, 2026Supply chain security/malware

Cybersecurity researchers have discovered two malicious packages in the Python Package Index (PyPI) repository that contain the ability to deliver a remote access trojan (RAT) while masquerading as a spell checker.

The packages named Spellcheckerpy and Spellcheckpy are currently not available for download, but they were previously downloaded over 1,000 times together.

“Hidden within the Basque dictionary file was a base64-encoded payload that downloaded a full-featured Python RAT,” said Aikido researcher Charlie Eriksen. “The attackers first published three ‘dormant’ versions with the payload present and no triggers, then flipped the switch with spellcheckpy v1.2.0 and added an obfuscated execution trigger that fires the moment SpellChecker is imported.”

Unlike other packages that hide malicious functionality within the “__init__.py” script, the attackers behind the campaign were found to add a payload within a file named “resources/eu.json.gz” that contains Basque frequencies from the legitimate pyspellchecker package.

cyber security

Although this function appears simple and harmless, when the archive file is extracted using the test_file() function with the parameter test_file(“eu”, “utf-8”, “spellchecker”), it triggers malicious behavior and retrieves a Base64-encoded downloader hidden under the key “spellchecker” in the dictionary.

Interestingly, the first three versions of the package only fetched and decoded the payload, but did not execute it. However, that changed with the release of Spellcheckpy version 1.2.0, published on January 21, 2026, which now allows payloads to be executed as well.

The first stage is a downloader designed to retrieve a Python-based RAT from an external domain (‘updatenet’).[.]work”). It can fingerprint compromised hosts, parse and execute commands received. This domain was registered in late October 2025 and is associated with 172.86.73.[.]139 is an IP address managed by RouterHosting LLC (also known as Cloudzy), a hosting provider with a history of serving a group of nations.

This is not the first time a fake Python spell checker has been detected on PyPI. In November 2025, HelixGuard announced the discovery of a malicious package named “spellcheckers” that has the ability to retrieve and execute RAT payloads. These two attacks are suspected to be the work of the same attacker.

This development coincides with the discovery of several malicious npm packages that facilitate data theft and target cryptocurrency wallets.

flockiali (1.2.3-1.2.6), opresc (1.0.0), prndn (1.0.0), oprnm (1.0.0), and operni contain single JavaScript files that, when loaded, are used by Microsoft as part of a targeted spear-phishing campaign that attacks employees at certain industrial and energy companies in France, Germany, Spain, the United Arab Emirates, and the United States. A branded fake login screen will appear. ansi-universal-ui (1.3.5, 1.3.6, 1.3.7, 1.4.0, 1.4.1). It masquerades as a UI component library but deploys a Python-based stealer called G_Wagon that steals web browser credentials, cryptocurrency wallets, cloud credentials, and Discord tokens into an Appwrite storage bucket.

cyber security

This disclosure comes at the same time that Aikido highlighted the threat associated with slopsquatting, where an artificial intelligence (AI)-powered agent hallucinates a non-existent package, which can then be used by threat actors to push malicious code to downstream users.

In one case highlighted by the supply chain security firm, a fictitious npm package named “react-codeshift” was configured with a large language model in mid-October 2025 and has since been referenced by 237 GitHub repositories, some of which even told AI agents to install it.

“How did it spread across 237 repositories? Agent skill files. Copied and pasted, forked, translated into Japanese, and never verified,” Eriksen said. “Skills are new code. They don’t look alike. Markdown and YAML, plain instructions. But they’re executable. The AI ​​agent follows them without asking, ‘Does this package actually exist?'”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFree AI training available to all adults in the UK
Next Article UK hydrogen industry poised for expansion, but policy slows momentum
user
  • Website

Related Posts

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

March 5, 2026

FBI and Europol seize LeakBase forum used to trade stolen credentials

March 5, 2026

149 hacktivist DDoS attacks hit 110 organizations in 16 countries after Middle East conflict

March 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Livermore Computing: Accelerating excellence in HPC

Strategies for next-gen medical technologies

Europol-led operation destroys Tycoon 2FA Phishing-as-a-Service, linked to 64,000 attacks

FBI and Europol seize LeakBase forum used to trade stolen credentials

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.