Divide and Hide: How Malicious Code Lived on PyPI for 3 months
Blog post from Endor Labs
Malicious packages on open source repositories like PyPI and npm often contain simple, easily detectable code, but a new variant demonstrates more sophisticated obfuscation tactics by spreading harmful functions across different files and packages. The malware, which aims to hijack Instagram accounts by extracting session identifiers from Chrome cookies on Windows, uses divided code to make detection harder. Key functions are distributed without declaring dependencies, complicating detection efforts and necessitating a comprehensive analysis of all files and packages together, which is resource-intensive compared to simple pattern searches. This sophisticated evasion technique highlights the ongoing arms race between attackers and defenders in cybersecurity, demonstrating how adversaries continually evolve to bypass detection systems. Despite these efforts, the packages gisi and ttlo, uploaded on April 16th and removed on July 7th, achieved relatively high download numbers due to the complexity of their obfuscation methods, underlining the challenges in effectively policing open source repositories.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.