
Malicious actors deployed fake Python package images, targeting the topgg community with over 170,000 members. The malware searches browsers, Telegram, and computers, stealing sensitive data including cryptocurrency wallets. Adversaries added over 400 malicious packages to PyPI, with one containing an infostealer.
Python Users: BIPClip Is After Your Bitcoin Wallet, Via PyPI https://t.co/bfACQIxZ75 #DataSecurity #PythonProgramming #Programming https://t.co/c6wsyDR6l8
An adversary has been adding Python based malware to PyPI for over a year now, adding over 400 malicious packages. And, this one with my name in it (... alongside some hate speech and profanity.) Deobfuscated payload is an infostealer. Hat tip to @sudo_Rem for flagging. https://t.co/LQ6pHrHnOQ
According to checkmarx, malicious actors deployed fake Python package images, and the code repository of the topgg community (170,000+ members) was attacked. The malware searches browsers, Telegram, computers and steals sensitive data; it searches cryptocurrency wallet and steals…


