• News/
  • https://www.theregister.com/2024/03/25/python_package_malware/

Over 170K users caught up in poisoned Python package ruse

The Register
·
Matthew Connatser
·
Published Mar 25, 2024
·
Updated

More than 170,000 users are said to have been affected by an attack using fake Python infrastructure with "successful exploitation of multiple victims." According to CheckMarx, members of the Top.gg GitHub organization – a top resource for Discord bot makers – as well as other developers were targeted, and it all hinged on various supply chain attack techniques to distribute malware-infected Python PyPI packages. That malware stole data from people's browsers, Discord app, crypto wallets, and files that matched certain keywords. As of now, it's not clear where this data was sent. There were multiple prongs to this remarkably complicated attack: clones of popular Python packages such as Colorama, a doppelganger or typosquatted domain for Python packages, and code obfuscation. Also reported are account break-ins across trusted GitHub community members. All of these tactics were used to successfully steal user data from an undetermined number of developers. The malicious Python packages were uploaded in November 2022, but the attack didn't start in earnest until last February when the doppelganger domain was registered. The official PyPI domain is pythonhosted.org, though the similar pypihosted domain (now taken down by Cloudflare) was available and the attacker registered it. The attacker made sure that real URL and the fake URL strings looked nearly identical. In fact, the only difference between the two was the domain name, pythonhosted versus pypihosted. The fake Python pack...

Read full article

Affected Software

4 affected components
Python PyPI
Python colorama
GitHub Top.gg
GitHub editor-syntax
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a security incident involving a malicious Python package that has affected over 170,000 users.

2

What security implications are discussed?

The article highlights the successful exploitation of multiple victims through poisoned Python package infrastructure.

3

Which software or packages are primarily affected by this attack?

The affected software includes the Python Package Index (PyPI), the Colorama package, and resources associated with GitHub organizations Top.gg and editor-syntax.

4

How did the attack affect users of the Python packages?

Users were compromised due to the installation of malicious packages that were masquerading as legitimate software.

5

What actions can users take to protect themselves from similar attacks?

Users should verify the authenticity of packages and maintain updated security practices to mitigate risks from malicious software.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203