Junglewise Threat Intelligence

spam PyPI package compromised with malicious releases

Severity: info · Published 2024-08-30

Vendors: PyPI.

Executive brief

The spam Python package on PyPI was compromised through a phishing attack that stole maintainer credentials, allowing attackers to publish malicious versions containing code that exfiltrated environment variables and downloaded malware at installation time. Any developer or application that installed the compromised versions (2.0.2 and 4.0.2) may have had their systems compromised, exposing sensitive credentials and enabling arbitrary code execution.

Technical details

The vulnerability stems from account takeover via phishing: attackers created a fake PyPI login page (sites.google.com/view/pypivalidate) that harvested credentials, which were sent to linkedopports.com. With stolen credentials, attackers gained control of legitimate project accounts and published malicious releases containing code that extracted environment variables and executed remote malware. The attack affected multiple projects including spam (versions 2.0.2, 4.0.2), and hundreds of additional typosquatted packages. Accounts lacking hardware security key protection were vulnerable; those with hardware 2FA were not compromised. PyPI removed malicious releases and temporarily froze affected maintainer accounts.

Affected products

  • PyPI spam 2.0.2, 4.0.2

Timeline

  • 2024-08-30: disclosed: Advisory published; original incident occurred in August 2022

References

Related threats