Two Typosquatting Python Packages Exploit Discord CDN to Dep...
Blog post from Socket
Two typosquatting Python packages, 'enchantv' and 'vibrant,' were identified as malicious by the Socket Research Team, exploiting the Discord CDN to deploy harmful payloads aimed at data theft and system manipulation. These packages, imitating popular Python libraries, contained base64 encoded payloads in their setup files that download and execute a batch script from a Discord CDN, potentially compromising user systems by collecting sensitive information such as WiFi passwords, crypto wallet data, and Discord tokens. The script operates by checking for administrative privileges, executing system commands, and sending extracted data to Discord webhooks, while also using a GitHub-hosted executable to facilitate data exfiltration. Before being removed from the PyPI registry, 'enchantv' and 'vibrant' accumulated 279 and 7,697 downloads, respectively, indicating a significant exposure risk to users searching for legitimate packages. The packages' malicious actions were obfuscated within their code, suggesting that either an individual or a group might be behind their distribution.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.