banner Expire 1 October 2024
Ad Ends 13 October 2024
banner Expire 1 November 2024
banner Expire 29 September 2024
ad End 18 October 2024
banner Expire 18 October 2024
banner Expire 20 October 2024
Ad Ends 13 October 2023
What's new
banner Expire 15 October 2024
Kfc CLub
Western union transfer
CrdCrew.cc Carding forum
UniCvv
Ad expire at 5 August 2024
adv exp at 23 August 2024
Carding.pw carding forum

File_closed07

TRUSTED VERIFIED SELLER
Staff member
Joined
Jun 13, 2020
Messages
7,006
Reaction score
908
Points
212
Awards
2
  • trusted user
  • Rich User
Malicious Python packages stole Discord tokens and credit card details

Two packages allowed a remote attacker to run malicious commands on the victim's device.


Operators of the official repository of Python Package Index (PyPI) components have removed eight libraries (pytagora, pytagora2, noblesse, genesisbot, are, suffer, noblesse2 and noblessev2) containing malicious code.

The malicious packages were detected by the JFrog cybersecurity team and were grouped into two categories based on their malicious operations. Two packages (pytagora and pytagora2) allowed a remote attacker to run malicious commands on the victim's device, forcing the infected system to connect to the attacker's IP address via TCP port 9009 and then execute any malicious Python code.

The other six packages (noblesse, genesisbot, are, suffer, noblesse2, and noblessev2) worked primarily to steal data. Once installed on a computer, they stole data, focusing on general system information, Discord tokens and user payment card information (stolen from installed browsers Google Chrome, Opera, Brave, etc.).

These eight libraries have been downloaded more than 30,000 times before being removed from the PyPI repository.
 
Ad End 1 October 2024
Top