Malicious PyPI Package Exploits Deezer API for Coordinated M...
Blog post from Socket
Researchers from Socket have discovered a malicious Python package named `automslc` on PyPI, designed to exploit Deezer's API for unauthorized music downloads, effectively engaging in coordinated music piracy. This package, initially released in 2019 and downloaded over 100,000 times, masquerades as a tool for music automation and metadata retrieval but covertly bypasses Deezer's access restrictions by embedding hardcoded credentials and communicating with a command and control (C2) server. `automslc` logs into Deezer to harvest metadata and request full-length streaming URLs, downloading complete audio files in violation of Deezer’s API terms, which only allow 30-second previews. The package communicates with a remote server to update download statuses and submit metadata, centralizing control and enabling the threat actor to monitor the distributed operation while exposing critical track details. The operation, directed by a threat actor using aliases like "hoabt2" and "Thanh Hoa," utilizes legitimate endpoints for metadata retrieval and URL generation, evading some detection mechanisms. The package's infrastructure includes a connection to the IP address `54.39.49[.]17` and the domain `automusic[.]win`, both integral to its command and control operations. This case highlights the importance of securing APIs against abuse, as it exploits Deezer's API in ways that modern security frameworks aim to prevent.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.