Malicious Python packages are stealing vital data, and have been downloaded thousands of times already

No Image Available

Published on April 7, 2025 | Category: tech

Malicious Python packages are stealing vital data, and have been downloaded thousands of times already

News
By Sead Fadilpašić published

Three malicious packages have roughly 40,000 downloads between them

The Python banner logo on a computer screen running a code editor.
(Image credit: Shutterstock / Trismegist san)

  • Researchers found three malicious PyPI packages, two targeting bitcoin developers, and one WooCommerce stores
  • Two are designed to steal data, and the third to test for valid credit cards
  • All three have since been removed from the repository

Multiple open source software packages on the Python Package Index (PyPI) repository were found to be malicious, likely compromising thousands of devices, experts have warned.

Cybersecurity researchers at ReversingLabs found two malicious packages, “bitcoinlibdbfix” and “bitcoinlib-dev”, which cumulatively have around 2,000 downloads.

They claim to be a fix for a legitimate Python module named “bitcoinlib”, which contains features for creating and managing cryptocurrency wallets.

Monitor your credit score with TransUnion starting at $29.95/month

Monitor your credit score with TransUnion starting at $29.95/month

TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnion’s advanced risk assessment tools.

Preferred partner (What does this mean?)

View Deal

WooCommerce stores also under attack

Recently, the community discussed an issue related to how the package generates error messages.

The crooks saw this as an opportunity, created the two malicious packages and jumped into the conversation in an attempt to distribute them. It doesn’t seem to have worked: “The malicious content of that library was detected by the package contributors and the comments were deleted,” ReversingLabs said.

Both libraries attempted a similar attack, the researchers further explained. The idea was to overwrite the legitimate ‘clw cli’ command with malicious code, exfiltrating sensitive database files.

At the same time, researchers from Socket found a third package, which doesn’t target bitcoin developers, but rather WooCommerce stores. Furthermore, this package doesn’t even try to hide its true intentions, and instead is “openly malicious”. Despite being obvious malware, it still managed to rake in 37,217 downloads.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

The malware is called “disgrasya” and works as a fully automated carding script. "The malicious payload was introduced in version 7.36.9, and all subsequent versions carried the same embedded attack logic," Socket said.

Carding is a type of cybercrime where stolen credit card information is used to make unauthorized purchases or test if the card is still active. Since criminals often buy these card details from the dark web, whoever built and distributed disgrasya could have profited greatly from it.

Via The Hacker News

You might also like

  • Popular Python AI library hacked to deliver malware
  • We've rounded up the best password managers
  • Take a look at our guide to the best authenticator app
TOPICS
Sead Fadilpašić

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

More about security
Abstract image of cyber security in action.

PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam

A file and folder transferring data with a red warning mark indicating malware.

Kellogg reveals data breach, but it's lacking any real crunch

Latest
Samsung Galaxy S25 home screen with Now Brief widget

Your Samsung Galaxy S25 just got a huge free Gemini upgrade that gives your AI assistant eyes

See more latest
Most Popular
Samsung Galaxy S25 home screen with Now Brief widget
Your Samsung Galaxy S25 just got a huge free Gemini upgrade that gives your AI assistant eyes
Characters wearing light suits in Tron: Ares
Disney's cult sci-fi saga reboot is back with a Tron: Ares trailer that sees the sequel leave the Grid
Abstract image of cyber security in action.
PoisonSeed campaign hijacks business CRM and email accounts to send out huge amounts of spam
BenQ PD2700U in a home office showing the Windows background
Windows 11’s rumored Start menu redesign could mean it eats up a huge chunk of desktop space for some users – although it can be tamed
An Nvidia GeForce RTX 4060 Ti
Keen to buy an RTX 5060 Ti? Benchmarks and more rumored sightings suggest you don’t have long to wait for Nvidia’s next GPU
Tom Cruise swings from an aeroplane undercarriage in the final Mission Impossible movie
New Mission Impossible trailer shows off Tom Cruise's latest stunts in the final chapter of Paramount's action spy series
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, April 8 (game #1170)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, April 8 (game #667)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Tuesday, April 8 (game #401)
Walton Goggins and Aimee Lou Wood hug while on a beach
The White Lotus season 3 finale has Mike White already thinking of where the hit Max series should go next

Related Articles

Spotify is about to be flooded with AI-made ads, and I wonder if it will make much of a difference to businesses

Spotify’s new AI-powered ad tool may not be the solution they claim....

Read More
CinemaCon 2025 live – first Avatar 3 reaction, juicy Fantastic Four news,

CinemaCon 2025 is officially underway – here are all new movie announc...

Read More
NYT Wordle today — answer and my hints for game #1385, Friday, April 4

Looking for Wordle hints? I can help. Plus get the answers to Wordle t...

Read More