Typosquatting on PyPI: Malicious Package Mimics Popular 'bro...
Blog post from Socket
A malicious Python package named "browser-cookies3" was identified on PyPI, mimicking the legitimate "browser-cookie3" library, by adding an extra 's' to deceive developers into downloading it. This malicious package, once installed, can steal sensitive information such as passwords, screenshots, webcam images, and Discord tokens, exfiltrating them to a Discord webhook. The threat actor utilized PyInstaller to disguise the malicious Python script as a Windows executable, and the package's setup script was crafted to automatically execute the malicious code during installation. This incident is a notable example of typosquatting, a technique increasingly used in software supply chain attacks, where attackers create packages with names similar to legitimate ones to spread malware. The legitimate "browser-cookie3" library, which assists in loading cookies for HTTP requests, has been downloaded over 3 million times since 2015. Socket's Threat Research Team detected the malicious package, emphasizing the need for developers to verify package authenticity and integrate security tools to prevent such attacks, while also taking steps to remove the harmful package from the registry.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.