Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Malicious Python Package Typosquats Popular 'fabric' SSH Lib...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
953
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious Python package named "fabrice" has been discovered by the Socket Research Team, which mimics the popular "fabric" SSH library to exfiltrate AWS credentials from unsuspecting developers. The package has been downloaded over 37,000 times since 2021 and is designed to operate on both Linux and Windows systems by executing platform-specific scripts, creating backdoors, and establishing persistence through scheduled tasks. It uses obfuscated URLs and a VPN-based proxy server to covertly send stolen data to a remote server, making it difficult to trace. The attack highlights the ongoing threat of typosquatting in open-source software repositories and the importance of using security tools to detect such threats early. The Socket app for GitHub provides continuous monitoring and advanced security checks to identify malicious packages. The team has reported "fabrice" to the PyPI team for takedown, urging developers to verify dependencies and utilize tools to prevent potential compromises.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.