450 Packages and Phishing Campaign against PyPI Maintainers

This Week in Malware - 450 Packages and a Phishing Campaign against PyPI Maintainers

August 26, 2022
By Aaron Linskens

This week in malware, we discovered and analyzed 450 packages flagged as malicious, suspicious, or due to dependency confusion attacks.

Also this week, a phishing email campaign targeted PyPI maintainers in attempts to compromise accounts and inject malware into the registry's packages.

Additionally, Sonatype's director of information security explored the connection between security and procurement.

Ongoing Phishing: Email Campaign Still Trying to Catch PyPI Maintainers Unawares

An ongoing phishing attack seeks to steal PyPI maintainer credentials and lace their legitimate packages with malware.

Reportedly the first known phishing campaign against PyPI, the scheme attempts to fool maintainers into running a purported Google-implemented "mandatory validation process" or risk removal from the registry.

Any unsuspecting developer who clicks through and provides credentials via a lookalike login page unknowingly exposes their packages for abuse. Hijacked versions of packages then download a malware file from a remote server.

PyPI removed affected releases, such as "spam" (versions 2.0.2 and 4.0.2) and "exotel" (version 0.1.6), froze compromised maintainer accounts, and removed "several hundred typosquats that fit the same pattern." Registry admins remain active to identify any additional malicious releases.

For more information, see Ax Sharma's BleepingComputer article.

The Long List of This Week's Malicious Packages

We caught the following this week via Sonatype's automated malware detection system:

These discoveries follow our report last week of dependency confusion PoCs and typosquats dropping malicious cryptominers.

Additionally, last week Ax Sharma published a deep dive into 200+ malicious cryptomining packages that flooded npm and PyPI registries.

Turn on Sonatype Firewall for Automatic Protection

As a DevSecOps organization, we remain committed to identifying and halting attacks, such as those mentioned above, against open source developers and the wider software supply chain.

Users of Sonatype Firewall can rest easy knowing that such malicious packages would automatically be blocked from reaching their development builds.

Sonatype Firewall instances will automatically quarantine any suspicious components detected by our automated malware detection systems, while a researcher is in progress, thereby keeping your software supply chain protected from the start.

Sonatype's world-class security research data, combined with our automated malware detection technology, protects your developers, customers, and software supply chain from infections.

Written by Aaron Linskens
Aaron is a technical writer at Sonatype. He works at a crossroads of technical writing, developer advocacy, and information design. He aims to get developers and non-technical collaborators to work better together in solving problems and building software.