Fallout in python, Aug 24 – Aug 30

What we caught this week while monitoring over 163,107,774 artifacts across 47 ecosystems. Campaigns that impact multiple packages are collapsed into a single entry with their siblings.

FRIDAY

Fri Aug 28 · 1 catch · 0 waves · 1 single
well-knownwell-known/toolsmicro-behaviors/communicationsmicro-behaviorsmetadatametadata/archobjectives/anti-analysisobjectives/executionmicro-behaviors/dataobjectivesobjectives/anti-static+8 27d
RPatcher 2.0.2 python 27 days ago

APK patching, SSL bypass, Pine hooking

payload/encoded

THURSDAY

Thu Aug 27 · 3 catches · 0 waves · 3 singles
micro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osobjectivesobjectives/exfiltration 28d
ekx-report-utils 0.2.0 python ✓ 28 days ago

DNS exfiltration of sandbox data

oob/endpoint
micro-behaviors/communicationsmicro-behaviorsobjectives/command-and-controlmicro-behaviors/datamicro-behaviors/processmicro-behaviors/fsmicro-behaviors/osobjectivesobjectives/exfiltration 28d
ekx-report-utils 0.3.0 python ✓ 28 days ago

DNS exfiltration of sensitive data

oob/endpoint
micro-behaviorsmicro-behaviors/datamicro-behaviors/processobjectivesobjectives/discoverymetadatametadata/packageobjectives/supply-chain 28d
msrcpoc 99.1.9 python ✓ 28 days ago

Malicious PyPI package, executes commands

account/enumtrojanized/package

WEDNESDAY

Wed Aug 26 · 1 catch · 0 waves · 1 single
well-known/appwell-knownmicro-behaviors/fsmicro-behaviorsmetadatametadata/buildobjectives/command-and-controlobjectives/anti-analysisobjectives/anti-staticobjectives/executionobjectives+17 29d
BetterSQLi 1.3.3 python 29 days ago

SQLi toolkit with embedded exploit payloads

eval/remoteexploit/sql-injection

TUESDAY

Tue Aug 25 · 2 catches · 0 waves · 2 singles
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/collectionobjectives/executionobjectives/impactmicro-behaviors/dataobjectivesobjectives/command-and-controlobjectives/exfiltration+6 30d

Keylogger, screen capture, C2, exfiltration

channel/messagingmessaging/telegram
micro-behaviors/communicationsmicro-behaviorsmetadatametadata/packageobjectives/collectionobjectives/executionobjectives/impactmicro-behaviors/processobjectivesobjectives/command-and-controlobjectives/exfiltration+6 30d

Telegram-controlled remote desktop malware

channel/messagingmessaging/telegram

MONDAY

Mon Aug 24 · 3 catches · 0 waves · 3 singles
well-knownwell-known/libmetadatametadata/buildobjectives/impactobjectives/lateral-movementthird_partyobjectivesobjectives/credential-accessmicro-behaviors/cryptomicro-behaviors+6 31d
dploot 4.0.0 python 31 days ago

Credential theft and lateral movement tool

browser/chromiumsymmetric/key
objectives/command-and-controlwell-knownwell-known/librarymicro-behaviors/communicationsmicro-behaviorsmetadata/packagemetadataobjectives/discoveryobjectivesobjectives/credential-accessobjectives/privilege-escalation+7 31d
pwnrm 1.2.6 python 31 days ago

AD post-exploitation shell

exploit/vulnerabilitiesdump/system
micro-behaviorsmicro-behaviors/communicationsobjectives/supply-chainobjectivesmetadatametadata/package 31d
multyproccess 2.32.3 python ✓ 31 days ago

Typosquatting with hidden payload

hidden-payload/packageimpersonation/brand
O objectives H behaviours Md metadata · a group subscript counts categories, an atom subscript subcategories