Home / Companies / Endor Labs / Blog / Post Details
Content Deep Dive

Divide and Hide: How Malicious Code Lived on PyPI for 3 months

Blog post from Endor Labs

Post Details
Company
Date Published
Author
Henrik Plate
Word Count
685
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Malicious packages on open source repositories like PyPI and npm often contain simple, easily detectable code, but a new variant demonstrates more sophisticated obfuscation tactics by spreading harmful functions across different files and packages. The malware, which aims to hijack Instagram accounts by extracting session identifiers from Chrome cookies on Windows, uses divided code to make detection harder. Key functions are distributed without declaring dependencies, complicating detection efforts and necessitating a comprehensive analysis of all files and packages together, which is resource-intensive compared to simple pattern searches. This sophisticated evasion technique highlights the ongoing arms race between attackers and defenders in cybersecurity, demonstrating how adversaries continually evolve to bypass detection systems. Despite these efforts, the packages gisi and ttlo, uploaded on April 16th and removed on July 7th, achieved relatively high download numbers due to the complexity of their obfuscation methods, underlining the challenges in effectively policing open source repositories.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.