Threat Advisory

Malicious PyPI Package Exposes Sensitive Data Through Credential Theft

Threat: Malicious Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A discovered malicious PyPI package poses a significant threat to all platforms that support PyPI installations. The package identified as zlibxjson is engineered to compromise user security by extracting and exfiltrating sensitive information from affected systems. This endangers both individual users and organizations that have installed this package.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A discovered malicious PyPI package poses a significant threat to all platforms that support PyPI installations. The package identified as zlibxjson is engineered to compromise user security by extracting and exfiltrating sensitive information from affected systems. This endangers both individual users and organizations that have installed this package.[emaillocker id="1283"]

 

The zlibxjson package contains an executable file packed with PyInstaller that unpacks and executes several Python (.pyc) files. Key components include discord_token_grabber.py, which extracts and decrypts Discord tokens from local files and sends them to an external server. Another component, get_cookies.py, targets and decrypts cookies from various web browsers, including Chrome, Firefox, Brave, and Opera, saving them to a file for potential exfiltration. Additionally, password_grabber.py accesses and decrypts saved passwords from browsers such as Google Chrome and Microsoft Edge, storing the sensitive information for unauthorized use.

 

The zlibxjson package represents a serious security risk, with its capabilities to steal sensitive data like Discord tokens, browser cookies, and saved passwords. To mitigate the threat posed by this malicious package, it is essential to implement effective detection mechanisms and adhere to rigorous security practices when managing software dependencies. Proactive measures are crucial to safeguarding user privacy and protecting against potential data breaches.

THREAT PROFILE:

Tactic Technique Id Technique
Defense Evasion T1078 Valid Accounts
T1027 Obfuscated Files or Information
Credential Access T1003 OS Credential Dumping
 Collection T1213 Data from Information Repositories
 T1056 Input Capture
 T1074 Data Staged
Command and Control T1071 Application Layer Protocol
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://www.fortinet.com/blog/threat-research/malicious-packages-hidden-in-pypl

[/emaillocker]
crossmenu