Target Industry
Indiscriminate, opportunistic targeting.
Overview
Cybersecurity researchers have uncovered malicious Python Package Index (PyPI) packages that target the Application Programming Interfaces (APIs) of popular social media platforms like Instagram and TikTok. These packages exploit vulnerabilities in the software supply chain, posing significant security risks.
Impact
The impact of this is likely to be severe, as developers may inadvertently incorporate these harmful packages into their projects. Sensitive user information, such as personal data and login credentials, can be exposed and exploited. Malicious packages can gain unauthorised access to user accounts, compromising privacy and security. Validated email lists are sold on the dark web, facilitating attacks like doxing, spamming, and credential stuffing.
Exploitation
The PyPI packages masquerade as legitimate, useful tools or libraries, tricking developers into incorporating them into their source code. The malicious packages interact with the APIs) of platforms like Instagram and TikTok to bypass standard security measures. The packages can collect sensitive information, with some allowing threat actors to execute arbitrary code remotely or create backdoors, giving them control over the affected systems.
Affected Python Packages
The affected Python packages which are no longer available on PyPI were: checker-SaGaF, steinlurks, and sinnercore.
Containment, Mitigations & Remediations
To mitigate the risks posed by malicious PyPI packages, it is highly recommended to:
- Use trusted sources and verify the authenticity of packages
- Keep all dependencies and packages up to date to benefit from the latest security patches and improvements
- Conduct regular code reviews to identify and remove any suspicious or unnecessary packages
- Educate developers about the risks of malicious packages and encourage best practices for secure coding.
Threat Landscape
The risk to organisations from malicious PyPI packages can vary depending on how widely the malicious package is integrated into the organisation’s projects and the type of data handled by any of the affected systems. The existing security protocols and measures are in place to detect and mitigate threats.
Threat Group
The malicious packages have been linked to the hacktivist group Phoenix Hyena. It is known for targeting Russian interests since the invasion of Ukraine in 2022.
Further Information













