malwarepypisupply-chaincredential-theft

Unit 42 — Malicious PyPI Packages

details a two-stage malware attack on PyPI using setup.py install scripts and W4SP Stealer to exfiltrate credentials, demonstrating that absence of a source repository and newly created single-package author accounts are key malware signals.

Summary

Unit 42 researchers discovered six malicious packages on PyPI in March 2023 — ligitgays, xboxredeemer, syntax-init, xboxlivepy, Ligitkidss, and tls-python — collectively accumulating 1,042 downloads before removal and targeting Windows users. All six were uploaded by freshly created accounts following a '1337' suffix naming pattern (Anne1337, Richard1337, Debbie1337, Christopher1337, Sara1337, Kevin1337), with usernames created within minutes of each other, and none had an associated GitHub repository. The two-stage attack used setup.py install scripts to download remote payloads from paste.bingner[.]com via urllib.request.urlopen into a NamedTemporaryFile to evade antivirus detection, then launched pythonw.exe to execute the payload — bypassing Windows SmartScreen since the script file was unsigned. The second stage deployed a configured W4SP Stealer 1.1.6 variant that decrypted DPAPI-protected browser credentials using CryptUnprotectData, extracted cookies, cryptocurrency wallet information, Discord friend lists and badge data, and exfiltrated everything through Discord webhooks. PyPI temporarily suspended new package and user registration on May 20, 2023 due to the broader rise in malicious activity. Unit 42 assessed this as a copycat attack imitating W4SP group techniques, noting the second stage was unencrypted and the packages did not use typosquatting.

Related Checks

PACKAGE_ACTIVE_MALWARE

All six packages contained active W4SP Stealer 1.1.6 malware that decrypted DPAPI-protected browser credentials, extracted cookies, cryptocurrency wallet data, and Discord account information, exfiltrating via Discord webhooks. Each package reached hundreds of downloads before removal.

Adverse Outcome

credential theft, cryptocurrency wallet compromise, and data exfiltration from developer machines that install the malicious package

Because

the packages were confirmed malicious by Unit 42 researchers and removed by PyPI along with the fraudulent accounts, demonstrating that active malware detection in registry advisories directly prevents consumption of packages containing known info-stealers

SOURCE_REPO_NOT_FOUND

None of the six malicious packages had an associated GitHub repository. Unit 42 explicitly identified this absence as a detection indicator, stating the packages 'lacked an associated GitHub repository, which is commonly found with legitimate packages.'

Adverse Outcome

inclusion of a package whose contents cannot be independently verified against source code, preventing detection of injected malicious payloads

Because

the researchers identified absence of a source repository as one of their primary suspicion signals, and all six confirmed-malicious packages shared this trait — indicating that malicious actors deliberately omit source repositories to prevent code inspection

PACKAGE_INSTALL_SCRIPTS

The attack executed malicious code in setup.py during package installation, using urllib.request.urlopen to download and exec to run remote payloads. The article states 'the attack is already carried out during the installation of the package' and notes these attacks 'can be launched with little security expertise.'

Adverse Outcome

arbitrary code execution on developer machines during package installation, before any application code imports or runs the package

Because

the article demonstrates that setup.py install scripts are the primary entry point enabling two-stage malware delivery — the install hook executes the downloader automatically, requiring no further action from the victim, making install-script detection a reliable proxy for preventing this attack class

PACKAGE_RELEASE_COOLDOWN

All six packages were uploaded within a short time frame by accounts created just before upload, with no prior history — the compressed timeline between account creation, package upload, and payload delivery is consistent with a rapid-fire malicious campaign.

Adverse Outcome

installing a recently published malicious package version before community vetting or security scanning can identify the threat

Because

the attack accumulated 1,042 downloads across six packages before detection and removal, demonstrating that packages published in rapid succession by new accounts can reach meaningful adoption before takedown — a cooldown period would have delayed consumer exposure during the critical early window

Gaps Analysis

Evidence

All six packages were uploaded by freshly created accounts whose usernames followed a '1337' suffix pattern and were created within minutes of each other, each having uploaded only a single package.

Blind Spot

Risk Guard evaluates package and source repository metadata but does not analyze registry author account characteristics such as account age, upload count, or coordinated account creation patterns.

Actionable Capability

Risk Guard would be better if it could flag packages published by newly created accounts with zero prior upload history, especially when multiple such accounts appear in a coordinated pattern.

Evidence

The attack used setup.py to download remote payloads via urllib.request.urlopen into a NamedTemporaryFile, then executed them via pythonw.exe to bypass Windows SmartScreen signature checking.

Blind Spot

Risk Guard detects the presence of install scripts but does not analyze their contents for behavioral indicators like remote code retrieval, temporary file execution, or unsigned binary invocation.

Actionable Capability

Risk Guard would be better if it could perform behavioral analysis on install scripts to flag remote payload download and execution patterns as high-confidence malware signals.

← Previous Next →