Home / Companies / Socket / Blog / Post Details
Content Deep Dive

PyPI Package Disguised as Instagram Growth Tool Harvests Use...

Blog post from Socket

Post Details
Company
Date Published
Author
Kush Pandya
Word Count
1,102
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious PyPI package masquerading as an Instagram growth tool called "imad213" was discovered to be harvesting user credentials and transmitting them to third-party bot services. Created by a threat actor known as im_ad__213, the package uses base64 encoding to conceal its true function and employs a remote kill switch via a Netlify-hosted file to control its execution. Presented professionally on GitHub, it misleads users into believing it is a legitimate tool by including a detailed README and safety tips, thus encouraging users to provide their Instagram credentials under the guise of boosting followers. Once executed, the malware saves the credentials locally and broadcasts them to ten different bot services, which may store, sell, or misuse the information. This orchestrated operation has been ongoing for nearly four years, highlighting a persistent and sophisticated credential harvesting scheme. The misuse of Instagram's API for such unauthorized purposes violates the platform's terms and can lead to account suspension, reduced content distribution, and potential identity theft for the users. The incident underscores the ongoing threat of social engineering and credential laundering networks, with potential for more complex attacks targeting multiple platforms in the future.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.