Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Monkey-Patched PyPI Packages Use Transitive Dependencies to ...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,056
Company Posts That Month
18
Language
English
Hacker News Points
-
Post removed?
No
Summary

A sophisticated supply chain attack on the Python Package Index (PyPI) was discovered by Socket's Threat Research Team, involving a threat actor using the alias cappership. The attack utilized a malicious package named semantic-types, which was embedded with a covert key-stealing payload, affecting the Solana blockchain's private keys. Five other packages depended on semantic-types, enabling transitive dependency installs that executed the malware without direct importation. The malware employed monkey patching to replace Solana key-generation methods at runtime, capturing and encrypting private keys with an RSA-2048 public key, and exfiltrating them via Solana Devnet transactions. The threat actor enhanced the credibility of these packages through polished README files linked to legitimate sources like Stack Overflow and GitHub. The packages have been downloaded over 25,900 times, posing a significant risk to developer environments. Security recommendations include inspecting nested dependencies, enforcing stricter CI/CD controls, and utilizing tools like the Socket GitHub app for identifying risky packages and monkey-patching behavior.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.