Malicious PyPi packages contained the W4SP Stealer malware

Home/BOTNET, Compromised, Exploitation, Internet Security, Malware, Security Advisory, Security Update/Malicious PyPi packages contained the W4SP Stealer malware

Malicious PyPi packages contained the W4SP Stealer malware

Five malicious packages were found on the Python Package Index (PyPI), stealing passwords, Discord authentication cookies, and cryptocurrency wallets from unsuspecting developers.

Having already been acquired by hundreds of software developers, these five packages have been removed from availability. These five packages and their download statistics are:

  1. 3m-promo-gen-api – 136 downloads
  2. Ai-Solver-gen – 132 downloads
  3. hypixel-coins – 116 downloads
  4. httpxrequesterv2 – 128 downloads
  5. httpxrequester – 134 downloads

Although Fortinet failed to provide details on the type of malware, BleepingComputer identified it as W4SP Stealer.

The W4SP Stealer malware starts by grabbing data from popular web browsers such as VPN extensions for Google Chrome, The Opera, Brave Browser, Yandex Browser and Microsoft Edge.

It then tries to steal authentication cookies from Discord, the Public Test Build (PTB), the Canary build, and the LightCord client for malicious use.

Following target websites:

  • Coinbase.com
  • Gmail.com
  • YouTube.com
  • Instagram.com
  • PayPal.com
  • telegram.com
  • Hotmail.com
  • Outlook.com
  • Aliexpress.com
  • ExpressVPN.com
  • eBay.com
  • Playstation.com
  • xbox.com
  • Netflix.com
  • uber.com

As package repositories such as PyPi and NPM, are now commonly used for distribution malware, developers must analyze the code in packages before him add in projects their.

Follow Us on: Twitter, InstagramFacebook to get the latest security news!

By | 2023-02-14T02:12:55+05:30 February 13th, 2023|BOTNET, Compromised, Exploitation, Internet Security, Malware, Security Advisory, Security Update|

About the Author:

FirstHackersNews- Identifies Security

Leave A Comment

Subscribe to our newsletter to receive security tips everday!