Malware Report
Title
Cloud Provider Credentials Targeted in New PyPI Malware Campaign
Report Author
Phylum Research Team
Published At
2023-10-09
Updated At
2023-10-09
Description
Over the weekend, Phylum’s automated risk detection alerted us to a series of publications surrounding packages on PyPI, all purporting to be some kind of cloud provider SDK or helper package. While these packages do, in fact, provide the purported functionality, they also surreptitiously ship the credentials off to
Malware Packages (5)
The following malware packages were identified in this report.
Package Type | Name | Attack Strategy | Package Author | Versions |
---|---|---|---|---|
Pypi Package | alibabacloud-oss2 | coinexchanged | ||
Pypi Package | aws-enumerate-iam | weiwang3056 | ||
Pypi Package | python-alibabacloud-sdk-core | coinexchanged | ||
Pypi Package | python-alibabacloud-tea-openapi | coinexchanged | ||
Pypi Package | tencent-cloud-python-sdk | hdhaibqbx | ||
Package Type | Name | Attack Strategy | Package Author | Versions |
Showing 1 to 5 of 5 entries