Malware & Info-Stealers 2022-2023 Incident #34

W4SP Stealer campaign

Estimated Financial Impact
5700+ downloads initial wave
Blast Radius
Discord tokens, browser creds, crypto wallets, credit cards

What Happened

A persistent multi-wave campaign on PyPI deploying W4SP Stealer via dozens of malicious packages. The malware stole Discord tokens, browser credentials, cryptocurrency wallets, and credit card data. Techniques evolved to include steganography for payload concealment. Copycat attacks emerged after the W4SP code leaked publicly.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_INSTALL_SCRIPTSPACKAGE_ACTIVE_MALWARE

How Every Tool Performed

3 Caught 0 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Sonatype (Nexus) Caught Nexus Firewall blocks known-malicious packages at ingestion
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← 241 cryptominer typosquats ESET 116-package cluster →