Malware & Info-Stealers 2023-2025 Incident #39

2025 cloud credential theft

Estimated Financial Impact
14100+ cumulative downloads
Blast Radius
AWS, Alibaba Cloud, Tencent Cloud tokens

What Happened

Twenty malicious PyPI packages stole AWS, Alibaba Cloud, and Tencent Cloud credentials. Three were dependencies of a popular GitHub project (accesskey_tools, 519 stars), creating a transitive infection vector reaching users who never installed the malicious packages directly.

✓

Risk Guard: Caught

PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWARE

How Every Tool Performed

2 Caught 1 Partial 3 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
Sonatype (Nexus) Partial Limited ecosystem coverage for this attack
Socket Caught Behavioral analysis detects malicious payload.
Snyk Missed No malware detection capability
Black Duck Missed No malware detection capability
Endor Labs Missed No malware detection capability
← pymafka Cobalt Strike JarkaStealer AI chatbot lure →