Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

The Sesame Workshop has won the Elevate Prize Catalyst Award for diagramming new paths for “Sesame Street”

Ben & Jerry co-founders have been arrested in the US Senate after protesting the war in Gaza | Protest News

Kennedy ensures that council funds for Head Start will not be cut

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Malicious PYPI package stole cloud tokens – 14,100 downloads before deleting
Identity

Malicious PYPI package stole cloud tokens – 14,100 downloads before deleting

userBy userMarch 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

March 15, 2025Ravi Lakshmanan Malware/Supply Chain Security

Malicious Pypi Packages

Cybersecurity researchers have fake libraries that disguise themselves as “time” related utilities for malicious campaigns targeting users of Python Package Index (PYPI) repository, but have hidden features to steal sensitive data, such as cloud access tokens.

Software supply chain security company ReverSinglabs said it has discovered a total of 20 sets of packages. The package has been downloaded cumulatively over 14,100 times –

Snapshot-Photo (2,448 downloads) Time Check Server (316 downloads) Time Check Server – Get (178 downloads) Time Server Analysis (144 downloads) Time Server Analyzer (74 downloads) Time Server Test (155 downloads) Download (151 downloads) (151 downloads) (5,496 downloads) Acloud-Clients (198 downloads) Acloud-Client-USES (294 downloads) Alicloud-Client (622 Downloads) Alicloud-Client-SDK (206 download) AMZCLIENTS-SDK (100 download) AWSCLOUD-CLIENTS-CORE (206 download) download) tclients-sdk (173 download) tcloud-python-sdks (98 download) tcloud-python-test (793 download)

The first set relates to the packages used to upload data to the threat actor’s infrastructure, while the second cluster consists of packages that implement cloud client functionality in several services, such as Alibaba Cloud, Amazon Web Services, and Tencent Cloud.

Cybersecurity

But they also use “time” related packages to remove cloud secrets. All identified packages have already been removed from Pypi at the time of writing.

Further analysis revealed that three packages, Acloud-Client, Enumer-IAM, and Tcloud-Python-Test, are listed as dependencies for a relatively popular Github project named AccessKey_tools, which have been forked 42 times and launched 519 times.

Malicious Pypi Packages

A source code commit was created on November 8, 2023 to reference Tcloud-Python-Test, indicating that the package can be downloaded in Pypi ever since. For each Pepy.tech statistics, the package has been downloaded 793 times so far.

This disclosure comes as Fortinet Fortiguard Labs said it discovered thousands of packages across Pypi and NPM. Some of them are known to include suspicious installation scripts designed to deploy malicious code during installation and communicate with external servers.

“Suspicious URLs are a key indicator of potentially malicious packages as they are used to download additional payloads, establish communication with command and control (C&C) servers, and are often used to control infected systems to attackers,” says Jenna Wang.

“In the 974 packages, such URLs are linked to the risk of data stripping, malware downloading, and other malicious actions. It is important to scrutinize and monitor external URLs of package dependencies to prevent exploitation.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTrump’s Columbia University arrests international university students for worrying
Next Article Russian captain of North Sea ship collision charged with manslaughter | Shipment News
user
  • Website

Related Posts

Samsung Patches CVE-2025-4632 Used for Mirai Botnet deployment via Magicinfo 9 Exploit

May 14, 2025

Bianlian and Ransomexx deploys SAP NetWeaver flaws and deploys Pipemagic Trojan

May 14, 2025

Xinbi Telegram Market is $840 million in crypto crime, romance fraud, North Korean laundry

May 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

The Sesame Workshop has won the Elevate Prize Catalyst Award for diagramming new paths for “Sesame Street”

Ben & Jerry co-founders have been arrested in the US Senate after protesting the war in Gaza | Protest News

Kennedy ensures that council funds for Head Start will not be cut

Students in Florida’s only public HBCU protest presidential candidate

Trending Posts

Ben & Jerry co-founders have been arrested in the US Senate after protesting the war in Gaza | Protest News

May 15, 2025

Incumbent Louis Arce will stop Bolivian presidential election amid slump in support | Election news

May 15, 2025

In Taiwan, AI Boom is questioning nuclear abandonment | Nuclear News

May 15, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

AI replaces humans: Klarna replaces 700 employees with AI, slashing the workforce by 40%

Voltra emerges from stealth for $1.8 million to launch “Charge,” a stripe-like API for EV chargers and microgrids.

AI infrastructure startup TensorWave raises $100 million to meet the rising demand for AI calculations

DataBricks acquires serverless database startup neon for $1 billion to boost AI agent development

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.