• News/
  • https://www.bleepingcomputer.com/news/security/malicious-pypi-packages-abuse-gmail-websockets-to-hijack-systems/

Malicious PyPI packages abuse Gmail, websockets to hijack systems

BleepingComputer
·
Bill Toulas
·
Published May 1, 2025
·
Updated

Seven malicious PyPi packages were found using Gmail's SMTP servers and WebSockets for data exfiltration and remote command execution. The packages were discovered by Socket's threat research team, who reported their findings to the PyPI, resulting in the removal of the packages. However, some of these packages were on PyPI for over four years, and based on third-party download counters, one was downloaded over 18,000 times. Here's the complete list shared by Socket: The 'Coffin' packages appear to be impersonating the legitimate Coffin package that serves as a lightweight adapter for integrating Jinja2 templates into Django projects. The malicious functionality Socket discovered in these packages centers on covert remote access and data exfiltration through Gmail. The packages used hardcoded Gmail credentials to log into the service's SMTP server (smpt.gmail.com), sending reconnaissance information to allow the attacker to remotely access the compromised system. As Gmail is a trusted service, firewalls and EDRs are unlikely to flag this activity as suspicious. After the email signaling stage, the implant connects to a remote server using WebSocket over SSL, receiving tunnel configuration instructions to establish a persistent, encrypted, bidirectional tunnel from the host to the attacker. Using a 'Client' class, the malware forwards traffic from the remote host to the local system through the tunnel, allowing internal admin panel and API access, file transfer, email exfiltr...

Read full article

Affected Software

3 affected components
Python Package Index malicious PyPi packages
npm crypto-encrypt-ts
PyPI Coffin
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the discovery of seven malicious PyPI packages that exploit Gmail's SMTP servers and WebSockets to hijack systems.

2

What security implications are discussed in the article?

The malicious packages facilitate data exfiltration and remote command execution, posing a significant security risk to affected systems.

3

What products or software are affected by these malicious packages?

The affected software includes various Python packages available on the Python Package Index, as well as npm packages like crypto-encrypt-ts.

4

Who discovered these malicious PyPI packages?

The packages were identified by Socket's threat research team, who reported their findings to the relevant authorities.

5

How do the malicious packages execute their attacks?

The malicious packages utilize Gmail's infrastructure to perform data exfiltration and execute commands remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203