None
EN
SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers
['The Hacker News', 'Sep', 'Ravie Lakshmanan']
The Hacker News
Cybersecurity researchers have discovered two new malicious packages in the Python Package Index (PyPI) repository that are designed to deliver a remote access trojan called SilentSync on Windows systems.
"SilentSync also extracts web browser data, including credentials, history, autofill data, and cookies from web browsers like Chrome, Brave, Edge, and Firefox."
sisaws (201 Downloads)secmeasure (627 Downloads)Zscaler said the package sisaws mimics the behavior of the legitimate Python package sisa, which is associated with Argentina's national health information system, Sistema Integrado de Información Sanitaria Argentino (SISA).
"The Python script retrieved from PasteBin is written to the filename helper.py in a temporary directory and executed."
"The discovery of the malicious PyPI packages sisaws and secmeasure highlight the growing risk of supply chain attacks within public software repositories," Zscaler said.
['rat'
'data'
'send'
'package'
'pypi'
'script'
'zscaler'
'developers'
'delivered'
'sisaws'
'targeting'
'silentsync'
'malicious'
'packages'
'windows'
'python']