Malware & Info-Stealers 2023-2024 Incident #36

Cool Package / pytoileur

Estimated Financial Impact
Keylogging, webcam, screenshots
Blast Radius
AI developer targeting (gpt-requests)

What Happened

A persistent PyPI campaign published packages described as "Cool package" with malicious payloads hidden using whitespace-encoded base64 in setup.py. Later packages specifically targeted AI developers with names like "gpt-requests." Capabilities included keylogging, webcam access, and screenshot capture.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_INSTALL_SCRIPTSPACKAGE_ACTIVE_MALWARE

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← ESET 116-package cluster requesys ransomware →