A persistent multi-wave campaign on PyPI deploying W4SP Stealer via dozens of malicious packages. The malware stole Discord tokens, browser credentials, cryptocurrency wallets, and credit card data. Techniques evolved to include steganography for payload concealment. Copycat attacks emerged after the W4SP code leaked publicly.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Caught | Nexus Firewall blocks known-malicious packages at ingestion |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |