Cyber Security

Malicious PyPI Packages Mimics a Legitimate Tools Attacking Crypto Wallets

Threat actors target the “PyPI” primarily due to its vast user base and the ease of distributing malicious packages within an “open-source ecosystem.”

The decentralized nature of “PyPI” complicates monitoring efforts which makes it an attractive platform for threat actors seeking to “compromise developer environments” and “disrupt the software supply chain.”

Checkmarx researchers recently found PyPI is under attack and discovered malicious crypto-stealing packages.

PyPI Packages Mimics Legitimate Tools

A malicious user on PyPI directed a sophisticated “supply chain attack” on 22nd September by “uploading multiple deceptive packages” like “AtomicDecoderss,” “TrustDecoderss,” “WalletDecoderss,” and “ExodusDecodes.”

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free

TrustDecoderss and ExodusDecodes (Source – Medium)

These packages presented themselves as legitimate tools for managing cryptocurrency wallets like “Atomic,” “Trust Wallet,” “Metamask,” “Ronin,” “TronLink,” and “Exodus.”

While appearing to help users recover “mnemonic phrases” (12-24 word backup passwords) and decrypt wallet data, the packages implemented a complex malware strategy through “dependency poisoning.”

Here the malicious code was hidden in supporting packages named “cipherbcryptors” and “ccl_leveldbases” rather than the main package, Checkmark added.

The attacker enhanced credibility via professionally crafted “README files” (documentation) with “fake download statistics” and “usage instructions.”

When users installed these packages, the hidden malicious code would activate and steal sensitive cryptocurrency data.

While it includes “private keys” and “mnemonic phrases,” which give the attackers complete access to victims’ cryptocurrency funds worth “millions of dollars.”

A sophisticated supply chain attack in the “Python ecosystem” using multiple layers of “deception” and “technical sophistication” is represented by the “cipherbcryptors” package. ⁤⁤

The malware employed “heavy code obfuscation techniques” to mask its true functionality while implementing a “dynamic C2 server infrastructure” that retrieved addresses externally rather than “hard-coding” them.

Attack flow (Source – Medium)

⁤The package remained dormant during “installation” to evade “security scans,” activating only when users called specific cryptocurrency functions. ⁤

The malware targeted various cryptocurrency wallets once it was triggered by searching for sensitive data.

While the sensitive data includes “private keys,” “mnemonic seed phrases,” “wallet balances,” and “transaction histories” in specific file locations and “data structures.” ⁤

Here below we have mentioned all the identified packages:-

  • atomicdecoderss
  • trondecoderss
  • phantomdecoderss
  • trustdecoderss
  • exodusdecoderss
  • walletdecoderss
  • ccl-localstoragerss
  • exodushcates
  • cipherbcryptors
  • ccl_leveldbases

⁤The stolen information was then “encoded” and “exfiltrated” to the attacker’s remote servers via a “carefully directed process.” ⁤⁤

This supply chain attack was particularly dangerous due to its combination of “false popularity metrics,” “detailed documentation,” “strategic package naming,” and the “ability to dynamically fetch and execute external code” without package updates. ⁤⁤

The architecture of the malware allowed it to bypass traditional “static analysis tools” while maintaining the flexibility to modify its attack patterns via “remote updates.” ⁤⁤

This illustrates the evolving sophistication of open-source software supply chain attacks.

IOCs

  • hxxps[:]//pastebin[.]com/raw/FZUp6ESH
  • hxxps://decry[.]in/check

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Free Webinar

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago