StackExchange missbraucht, um bösartige PyPi-Pakete als Antworten zu verbreiten

Teilen:

Threat actors uploaded malicious Python packages to the PyPI repository and promoted them through the StackExchange online question and answer platform.

The packages are named ‘spl-types,’ ‘raydium,’ ‘sol-structs,’ ‘sol-instruct,’ and ‘raydium-sdk’ and download scripts that steal sensitive data from the browser, messaging apps (Telegram, Signal, Session), and cryptocurrency wallet details (Exodus, Electrum, Monero).

The info-stealing malware can also exfiltrate files with specific keywords as well as take screenshots, and sends all the data to a Telegram channel.

Researchers at application security testing company Checkmarx say that while the packages were uploaded to PyPI on June 25 but received the malcicious component in an update on July 3.

The packages are no longer on PyPI they have already been downloaded 2082 times.

Abusing StackExchange

According to Checkmarx’s investigation, the attackers specifically targeted users involved in the Raydium and Solana blockchain projects.

The fact that Raydium does not have a Python library created an exploitation opportunity for the attackers, who used the name for their package without having to resort to typosquatting or other deception techniques.

To promote the packages to the right targets, the attackers created accounts on StackExchange and left comments under popular threads containing links to the malicious packages.

The chosen topics were related to the package names, and the answers given were of high quality, so victims could be tempted download the dangerous packages.

With over two thousand potential infections, estimating the impact of this campaign is difficult, but Checkmarx researchers presented a couple of victim examples in their report.

One case concerns an IT employee who had his Solana cryptocurrency wallet drained as a result of the infection.

In the second example, the malware captured a screenshot of the victim’s private key, which can be used to bypass MFA protections and hijack accounts even without the password.

Notably, that screenshot shows that Windows Virus and Threat Protection scans failed to catch the threat running on the victim’s device.

This tactic has been used in the past. A similar case was reported by Sonatype in May 2024 and involved promoting malicious Python packages on PyPI via StackOverflow answers.

Most software developers are helpful individuals, ready to whip up a script, or point to one that can make things easier. However, using a script from a legitimate platform is not enough as the author should also be trustworthy.

Even so, inspecting the code before using it is the best way to make sure that it has not been modified at a later time for malicious purposes, as it happened in the campaign described by Checkmarx.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
12:21 am, Juni 21, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
klarer Himmel
Luftfeuchtigkeit: 71 %
Druck: 1021 mb
Wind: 9 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 5%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0.25 mm 25% 9 mph 72 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
17° | 26°°C 1 mm 100% 16 mph 88 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
15° | 24°°C 0.2 mm 20% 14 mph 77 % 1017 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 12 mph 76 % 1017 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
17° | 20°°C 1 mm 100% 11 mph 82 % 1011 mb 0 mm/h
Today 1:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 5 mph 72 % 1020 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
17° | 18°°C 0 mm 0% 5 mph 68 % 1020 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 6 mph 56 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
27° | 27°°C 0 mm 0% 8 mph 34 % 1018 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 9 mph 25 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
33° | 33°°C 0 mm 0% 8 mph 25 % 1016 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 8 mph 28 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0.25 mm 25% 6 mph 42 % 1014 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,471.72
-1.60%
Ethereum(ETH)
€2,075.72
-5.34%
Fesseln(USDT)
€0.87
-0.01%
XRP(XRP)
€1.83
-2.51%
Solana(SOL)
€120.70
-5.38%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.140280
-5.53%
Shiba Inu(SHIB)
€0.000010
-3.02%
Pepe(PEPE)
€0.000009
-5.17%
Peanut das Eichhörnchen(PNUT)
€0.218243
13.10%
Nach oben scrollen