Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Typosquatting on PyPI: Malicious Package Mimics Popular 'bro...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
882
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

A malicious Python package named "browser-cookies3" was identified on PyPI, mimicking the legitimate "browser-cookie3" library, by adding an extra 's' to deceive developers into downloading it. This malicious package, once installed, can steal sensitive information such as passwords, screenshots, webcam images, and Discord tokens, exfiltrating them to a Discord webhook. The threat actor utilized PyInstaller to disguise the malicious Python script as a Windows executable, and the package's setup script was crafted to automatically execute the malicious code during installation. This incident is a notable example of typosquatting, a technique increasingly used in software supply chain attacks, where attackers create packages with names similar to legitimate ones to spread malware. The legitimate "browser-cookie3" library, which assists in loading cookies for HTTP requests, has been downloaded over 3 million times since 2015. Socket's Threat Research Team detected the malicious package, emphasizing the need for developers to verify package authenticity and integrate security tools to prevent such attacks, while also taking steps to remove the harmful package from the registry.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.