Malware & Info-Stealers 2023 Incident #35

ESET 116-package cluster

Estimated Financial Impact
10K+ total downloads
Blast Radius
53 projects; three injection techniques

What Happened

ESET identified 116 malicious packages across 53 PyPI projects delivering backdoors and cryptocurrency clipboard monitors. The campaign used three distinct injection techniques and accumulated 10,000+ total downloads at ~80 downloads per day.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARE

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← W4SP Stealer campaign Cool Package / pytoileur →