Target Industry

Indiscriminate, opportunistic targeting. 

Overview

Cybersecurity researchers have uncovered malicious Python Package Index (PyPI) packages that target the Application Programming Interfaces (APIs) of popular social media platforms like Instagram and TikTok. These packages exploit vulnerabilities in the software supply chain, posing significant security risks. 

Impact

The impact of this is likely to be severe, as developers may inadvertently incorporate these harmful packages into their projects. Sensitive user information, such as personal data and login credentials, can be exposed and exploited. Malicious packages can gain unauthorised access to user accounts, compromising privacy and security. Validated email lists are sold on the dark web, facilitating attacks like doxing, spamming, and credential stuffing. 

Exploitation

The PyPI packages masquerade as legitimate, useful tools or libraries, tricking developers into incorporating them into their source code. The malicious packages interact with the APIs) of platforms like Instagram and TikTok to bypass standard security measures. The packages can collect sensitive information, with some allowing threat actors to execute arbitrary code remotely or create backdoors, giving them control over the affected systems. 

Affected Python Packages

The affected Python packages which are no longer available on PyPI were: checker-SaGaF, steinlurks, and sinnercore. 

Containment, Mitigations & Remediations

To mitigate the risks posed by malicious PyPI packages, it is highly recommended to: 

  • Use trusted sources and verify the authenticity of packages 
  • Keep all dependencies and packages up to date to benefit from the latest security patches and improvements 
  • Conduct regular code reviews to identify and remove any suspicious or unnecessary packages  
  • Educate developers about the risks of malicious packages and encourage best practices for secure coding. 

 

Threat Landscape

The risk to organisations from malicious PyPI packages can vary depending on how widely the malicious package is integrated into the organisation’s projects and the type of data handled by any of the affected systems. The existing security protocols and measures are in place to detect and mitigate threats. 

Threat Group

The malicious packages have been linked to the hacktivist group Phoenix Hyena. It is known for targeting Russian interests since the invasion of Ukraine in 2022. 

Further Information

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content