Threat Advisory

Malicious ‘Lolip0p’ PyPi packages install info-stealing malware

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers recently discovered three PyPI (Python Package Index) packages containing a new zero-day exploit: 'colorslib,' 'httpslib,' and 'libhttps'. PyPI is a software repository for the Python programming language. Developers can upload their packages to PyPI, making them available for download and use by others. All three packages contain the malicious "setup.py" file, which attempts to launch PowerShell and downloads the executable "Oxyz.exe" from a suspicious URL. Researchers discovered that at least one of the terminated processes was collecting Discord tokens, implying that it could be part of a larger malware operation that targets data theft by stealing browser data, authentication tokens, and other data from compromised devices.[/subscribe_to_unlock_form]

Summary:

Researchers recently discovered three PyPI (Python Package Index) packages containing a new zero-day exploit: 'colorslib,' 'httpslib,' and 'libhttps'. PyPI is a software repository for the Python programming language. Developers can upload their packages to PyPI, making them available for download and use by others. All three packages contain the malicious "setup.py" file, which attempts to launch PowerShell and downloads the executable "Oxyz.exe" from a suspicious URL. Researchers discovered that at least one of the terminated processes was collecting Discord tokens, implying that it could be part of a larger malware operation that targets data theft by stealing browser data, authentication tokens, and other data from compromised devices.[emaillocker id="1283"]

Threat Profile:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/malicious-lolip0p-pypi-packages-install-info-stealing-malware/

[/emaillocker]
crossmenu