EXECUTIVE SUMMARY
A discovered malicious PyPI package poses a significant threat to all platforms that support PyPI installations. The package identified as zlibxjson is engineered to compromise user security by extracting and exfiltrating sensitive information from affected systems. This endangers both individual users and organizations that have installed this package.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A discovered malicious PyPI package poses a significant threat to all platforms that support PyPI installations. The package identified as zlibxjson is engineered to compromise user security by extracting and exfiltrating sensitive information from affected systems. This endangers both individual users and organizations that have installed this package.[emaillocker id="1283"]
The zlibxjson package contains an executable file packed with PyInstaller that unpacks and executes several Python (.pyc) files. Key components include discord_token_grabber.py, which extracts and decrypts Discord tokens from local files and sends them to an external server. Another component, get_cookies.py, targets and decrypts cookies from various web browsers, including Chrome, Firefox, Brave, and Opera, saving them to a file for potential exfiltration. Additionally, password_grabber.py accesses and decrypts saved passwords from browsers such as Google Chrome and Microsoft Edge, storing the sensitive information for unauthorized use.
The zlibxjson package represents a serious security risk, with its capabilities to steal sensitive data like Discord tokens, browser cookies, and saved passwords. To mitigate the threat posed by this malicious package, it is essential to implement effective detection mechanisms and adhere to rigorous security practices when managing software dependencies. Proactive measures are crucial to safeguarding user privacy and protecting against potential data breaches.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Defense Evasion | T1078 | Valid Accounts |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1003 | OS Credential Dumping |
| Collection | T1213 | Data from Information Repositories |
| T1056 | Input Capture | |
| T1074 | Data Staged | |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://www.fortinet.com/blog/threat-research/malicious-packages-hidden-in-pypl