New Malware Discovered in Python Package Index Attack
Cybersecurity experts have identified a new malware strain, dubbed ZiChatBot, lurking in three packages on the Python Package Index (PyPI). These packages, which have since been removed, were designed to stealthily infect both Windows and Linux systems.
The attack involved packages named uuid32-utils, colorinal, and termncolor, collectively downloaded over 2,400 times. Once installed, the malware extracts a DLL or shared object file that allows it to execute commands from a public chat app, Zulip, without traditional communication channels.
This incident primarily affects developers and organizations using these PyPI packages, potentially leading to data breaches and system compromises.
To protect against such threats, users are advised to avoid downloading unknown packages, regularly update their software, and implement security solutions that monitor for suspicious activities.
Risk Level: High
Source: View Original Report
