⤷ Title: Python Developers Beware: These Innocent PyPI Packages Secretly Hijack Your System with Deadly RAT!
════════════════════════
𐀪 Author: cybrNK
════════════════════════
ⴵ Time: Sat, 20 Sep 2025 19:35:46 GMT
════════════════════════
⌗ Tags: #trojan #hacking #pypi #python #cybersecurity
════════════════════════
𐀪 Author: cybrNK
════════════════════════
ⴵ Time: Sat, 20 Sep 2025 19:35:46 GMT
════════════════════════
⌗ Tags: #trojan #hacking #pypi #python #cybersecurity
Medium
Python Developers Beware: These Innocent PyPI Packages Secretly Hijack Your System with Deadly RAT!
The Python community has recently been shaken by the discovery of two malicious PyPI packages designed to deliver the Remote Access Trojan…
⤷ Title: PyPI Under Attack: New Malware ‘SilentSync’ Is Stealing Credentials
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Linux #macOS #PyPI ecosystem #Python #rat #SilentSync malware #supply chain attack #windows #Zscaler ThreatLabz
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 00:20:49 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #Linux #macOS #PyPI ecosystem #Python #rat #SilentSync malware #supply chain attack #windows #Zscaler ThreatLabz
Daily CyberSecurity
PyPI Under Attack: New Malware 'SilentSync' Is Stealing Credentials
A new supply chain attack on PyPI is delivering SilentSync, a Python RAT. The malware steals credentials and files from developers' systems.
⤷ Title: PSF Warns of Fake PyPI Login Site Stealing User Credentials
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 17:22:32 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Cyber Attack #Cybersecurity #Developers #Privacy #PSF #PyPI #Scam #security #Software
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 17:22:32 +0000
════════════════════════
⌗ Tags: #Security #Phishing Scam #Cyber Attack #Cybersecurity #Developers #Privacy #PSF #PyPI #Scam #security #Software
Hackread
PSF Warns of Fake PyPI Login Site Stealing User Credentials
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: New Phishing Campaign Targets PyPI Maintainers with Fake Domain
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:14:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #developer #open_source #phishing #PyPI #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:14:30 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #developer #open_source #phishing #PyPI #supply chain attack
Daily CyberSecurity
New Phishing Campaign Targets PyPI Maintainers with Fake Domain
A new phishing campaign is targeting PyPI maintainers with emails from a fraudulent pypi-mirror.org domain to steal credentials and compromise accounts.
⤷ Title: GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Sep 2025 04:13:07 +0000
════════════════════════
⌗ Tags: #Open Source Tool #CLI Tool #cybersecurity #GitHub Actions #Go #GuardDog #npm #PyPI #Supply Chain #VSCode Extensions
Penetration Testing Tools
GuardDog: The Open-Source CLI Tool for Hunting Malicious Packages in npm, PyPI, and More
GuardDog is a CLI tool that uses heuristics and Semgrep rules to scan for malicious npm, PyPI, Go, and VSCode packages, helping to secure the software supply chain.
⤷ Title: Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 03:01:21 +0000
════════════════════════
⌗ Tags: #Malware #backdoor #cybersecurity #JFrog #PyPI #SOCKS5 #SoopSocks #supply chain attack #Windows Service
Daily CyberSecurity
Backdoor Disguised as SOCKS5 Proxy: Malicious PyPI Package SoopSocks Grants Root Access
The malicious PyPI package SoopSocks masqueraded as a SOCKS5 proxy but secretly installed a Go-based backdoor with SYSTEM privileges, leaking system data to a Discord webhook.
⤷ Title: Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 14 Oct 2025 00:14:16 +0000
════════════════════════
⌗ Tags: #Malware #data exfiltration #Discord #npm #PyPI #RubyGems #Stealth #supply chain attack #Webhook C2
Daily CyberSecurity
Stealth C2: Hackers Abuse Discord Webhooks for Covert Data Exfiltration in npm, PyPI, and RubyGems Supply Chain Attacks
Malicious packages across npm, PyPI, and RubyGems are exploiting Discord webhooks as stealthy, resilient C2 endpoints to exfiltrate developer config files and sensitive host data.
⤷ Title: PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 00:15:58 +0000
════════════════════════
⌗ Tags: #Malware #PyPI #Python RAT #Remote Code Execution #spellcheckers #supply chain attack #Typosquatting #XOR encryption
Daily CyberSecurity
PyPI Typosquat Delivers Multi-Layer Python RAT, Bypassing Scanners with XOR Encryption
A malicious PyPI typosquat (spellcheckers) infected 950+ users. The package deploys an XOR-encrypted Python RAT via a hidden index file, granting full remote execution (exec()) and is linked to crypto scams.
⤷ Title: Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 00:12:25 +0000
════════════════════════
⌗ Tags: #Malware #cryptocurrency #DeFi Security #dYdX #npm malware #PyPi Malware #Python RAT #Remote Access Trojan #Socket Security #supply chain attack #Typosquatting #Wallet Stealer
Daily CyberSecurity
Poisoned Protocol: dYdX Supply Chain Attack Injects RATs into npm & PyPI
Critical dYdX supply chain attack: Compromised npm & PyPI packages steal seed phrases & deploy RATs. Remove @dydxprotocol/v4-client-js immediately.
⤷ Title: Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 10 Feb 2026 09:33:19 +0000
════════════════════════
⌗ Tags: #Malware #@dydxprotocol/v4_client_js #cryptocurrency security #dYdX #dydx_v4_client #malicious packages #npm #PyPI #seed phrase exfiltration #Socket Security #supply chain attack #Tech News 2026
Penetration Testing Tools
Surgical Strike on DeFi: How Hijacked dYdX Packages Drained Wallets via npm and PyPI
Security analysts at Socket have unmasked a surgical supply chain incursion targeting the libraries associated with the dYdX