Tuesday, March 4, 2025
Homecyber securityBeware of New Malicious PyPI packages That Steals Login Details

Beware of New Malicious PyPI packages That Steals Login Details

Published on

SIEM as a Service

Follow Us on Google News

Two malicious Python packages, Zebo-0.1.0 and Cometlogger-0.1, were recently detected by Fortinet’s AI-driven OSS malware detection system.

These packages, spotted on November 16 and November 24, 2024, respectively, represent significant threats to users by leveraging advanced malware techniques.

These findings underscore the critical importance of robust cybersecurity measures to protect against such sophisticated threats.

Malicious Behaviors of Zebo-0.1.0

The Zebo-0.1.0 package exhibits a range of malicious activities designed to surveil users, exfiltrate sensitive data, and maintain unauthorized system control.

Key malicious functionalities of Zebo-0.1.0 include:

  • Keylogging and Screen Capturing: The malware tracks every keystroke using the pynput library and captures screenshots at regular intervals via ImageGrab.
  • Data Exfiltration: Sensitive user data, such as keystrokes and screenshots, is uploaded to a remote Firebase database using obfuscated HTTP requests.
  • Persistence Mechanism: The package ensures prolonged presence in the user’s system by creating auto-executing Python scripts and batch files that initiate upon system startup.

The use of obfuscation techniques, including the encoding of malicious URLs, complicates detection efforts and highlights the sophisticated nature of this malware.

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

Threats Posed by Cometlogger-0.1

Cometlogger-0.1, another identified malicious package, goes a step further in sophistication.

It is capable of dynamically modifying files, stealing sensitive information, and bypassing security environments.

Noteworthy features include:

  • Webhook Injection and Information Theft: By injecting webhooks into multiple files, the malware facilitates the exfiltration of usernames, passwords, cookies, and cryptocurrency wallet data. Targeted platforms include Discord, Instagram, and various browsers.
  • Anti-VM Checks: The malware employs anti-virtualization techniques to avoid detection within sandbox environments used by researchers and security tools.
  • Dynamic File Modifications: The package manipulates Python files during runtime, enabling the execution of malicious commands and maintaining its stealthy presence.

A particularly alarming aspect of Cometlogger-0.1 is its ability to extract encrypted credentials and card data from browser storage, significantly escalating the risk of financial fraud and identity theft.

To mitigate the risk posed by these malicious packages, users and organizations are advised to follow these cybersecurity best practices:

  1. Disconnect and Scan: Immediately disconnect affected systems from the internet and perform a thorough malware scan using reputable antivirus software.
  2. Code Scrutiny: Avoid installing unverified Python packages and review the code of third-party scripts before execution.
  3. Network Monitoring: Implement intrusion detection systems to identify and block suspicious network activities.
  4. Awareness Training: Educate users on recognizing phishing schemes and avoiding unsafe downloads.

Fortinet customers remain protected against these threats through updated AntiVirus services, including FortiGate and FortiClient tools, which have been calibrated to detect and prevent these specific malware packages.

The discovery of Zebo-0.1.0 and Cometlogger-0.1 highlights increasing risks posed by open-source dependencies.

These malicious packages effectively demonstrate how attackers can use sophisticated techniques to bypass detection, exfiltrate data, and target both individuals and organizations.

Heightened vigilance, combined with advanced cybersecurity tools, remains critical in combating such threats.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Latest articles

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...

BigAnt Server 0-Day Vulnerability Lets Attackers Run Malicious Code Remotely

A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Docusnap for Windows Flaw Exposes Sensitive Data to Attackers

A recently disclosed vulnerability in Docusnap's Windows client software (CVE-2025-26849) enables attackers to decrypt...

CISA Warns of Active Exploitation of Microsoft Windows Win32k Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2018-8639, a decade-old Microsoft Windows...

Update Alert: Google Warns of Critical Android Vulnerabilities Under Exploit

Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under...