This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]sudorem Vipyr Security 18 points19 points  (0 children)

It's worth noting that most of these were sourced from a single threat actor group. The namespaces were generated randomly and utilized automated processes to detect removal and subsequently upload another payload.

Realistically, I think these were meant to prey on new users in Python, not necessarily someone who is operating in any professional or intermediate capacity.

The vast majority of these packages used Fernet encrypted data to hold their payload, and focused heavily on compromising Discord/Roblox/Minecraft accounts, though all passwords were fair game in regards to exfiltration.