Jump to content
  • Malicious PyPI packages hijack dev devices to mine cryptocurrency


    Karlston

    • 635 views
    • 2 minutes
     Share


    • 635 views
    • 2 minutes

    Malicious PyPI packages hijack dev devices to mine cryptocurrency

     

    This week, multiple malicious packages were caught in the PyPI repository for Python projects that turned developers' workstations into cryptomining machines.

     

    All malicious packages were published by the same account and tricked developers into downloading them thousands of times by using misspelled names of legitimate Python projects.

    Bash script pulls in miner

    A total of six packages containing malicious code infiltrated the Python Package Index (PyPI) in April:

     

    • maratlib
    • maratlib1
    • matplatlib-plus
    • mllearnlib
    • mplatlib
    • learninglib

     

    All came from user “nedog123” and the names of most of them are misspelled versions of the matplotlib legitimate plotting software.

     

    Ax Sharma, a security researcher at devops automation company Sonatype, analyzed the “maratlib” package in a blog post, noting that it was used as a dependency by the other malicious components.

     

    “For each of these packages, the malicious code is contained in the setup.py file which is a build script that runs during a package’s installation,” the researcher writes.

     

    While analyzing the package, Sharma found that it attempted to download a Bash script (aza2.sh) from a GitHub repository that is no longer available.

     

    Sharma tracked the author’s aliases on GitHub using open-source intelligence and found that the script’s role was to run a cryptominer called “Ubqminer” on the compromised machine.

     

    Ubqminer downloaded by bad PyPI package

     

    The researcher also notes that the malware author replaced the default Kryptex wallet address with their own to mine for Ubiq cryptocurrency (UBQ).

     

    In another variant, the script included a different cryptomining program that uses GPU power, the open-source T-Rex.

     

    PyPI package downloads T-Rex cryptomining program

     

    Attackers are constantly targeting open-source code repositories like PyPI [1, 2, 3], the NPM for NodeJS [1, 2, 3], or RubyGems. Even if the detection comes when the download count is low, as it typically happens, there is a significant risk as developers may integrate the malicious code in widely used projects.

     

    In this case, the six malicious packages were caught by Sonatype after scanning the PyPI repo with its automated malware detection system, Release Integrity. At detection time, the packages had accumulated almost 5,000 downloads since April, with “maratlib” recording the highest download count, 2,371.

     

     

    Malicious PyPI packages hijack dev devices to mine cryptocurrency


    User Feedback

    Recommended Comments

    There are no comments to display.



    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.
    Note: Your post will require moderator approval before it will be visible.

    Guest
    Add a comment...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.


  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...