Bitcoin Forum
November 16, 2024, 10:29:50 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Dormant PyPI Package: Deploying NovaSentinel Crypto Stealer  (Read 78 times)
Jating (OP)
Hero Member
*****
Offline Offline

Activity: 3122
Merit: 886


DGbet.fun - Crypto Sportsbook


View Profile
February 29, 2024, 12:26:10 AM
 #1

A package listed on the Python Package Index (PyPI) repository, which has been dormant since it first published to PyPI in April 2022. The package name is,

Code:
django-log-tracker

And it's repository is https://github.com/Ragib01/django_log_tracker. Django-log-tracker has been downloaded 3,866 times to date, with the rogue version (1.0.4) downloaded 107 times on the date it was published. While the linked GitHub repository hasn't been updated since April 10, 2022, the introduction of a malicious update suggests a likely compromise of the PyPI account belonging to the developer.

So most likely their could be some machines already being compromised and stealing cryptos. Below are the crypto address that have been used by criminals.



Quote
Ethereum address

has transacted 43 times on the Ethereum blockchain. It has received a total of 0.552653110090466539 ETH $1,649.89 and has sent a total of 0.52827227363384611 ETH $1,577.10. The current value of this address is 0.00 ETH $0.00.

Quote
And the Bitcoin address

has transacted 49 times on the Bitcoin blockchain. It has received a total of 0.33228144 BTC $17,166.00 and has sent a total of 0.33228144 BTC $17,166.00 (❗) The current value of this address is 0.00000000 BTC $0.00.

https://blog.phylum.io/dormant-pypi-package-updated-to-deploy-novasentinel-stealer/


So for Python developers out there, just be careful on what packages you used which includes: libraries, frameworks, utilities, and tools.

Malwares are everywhere now and very difficult for us crypto enthusiast as we are the target by this cyber criminals.

btc_angela
Hero Member
*****
Offline Offline

Activity: 2744
Merit: 551


DGbet.fun - Crypto Sportsbook


View Profile
February 29, 2024, 05:06:13 AM
Merited by Jating (1)
 #2

From the way I understand it, it was deployed years ago and there was no update whatsoever. So it means that the author, maybe his account was hack already was the sole culprit of having this package laid with crypto stealer malware.

So it went under the radar for cyber investigators, nevertheless after two years it has been found.

Unfortunately it has been used already and obviously someone has already fallen for this malware as it shows the Bitcoin and Ethereum address has been deposited and then withdrawn right away.

Dave1
Hero Member
*****
Offline Offline

Activity: 1498
Merit: 553



View Profile
February 29, 2024, 12:37:46 PM
 #3

At least it has been taken down already, although damage has been done obviously.

This criminals are not going to stop and will always find a way to insert their malware to even a unsuspecting PyPi package. And even if it is open source, we shouldn't trust anything but we have to verify.

And just imagine if they can insert it to a more popular PyPi package, it could be disastrous as many will fall for it and losing their crypto to this online criminals.

 
█▄
R


▀▀██████▄▄
████████████████
▀█████▀▀▀█████
████████▌███▐████
▄█████▄▄▄█████
████████████████
▄▄██████▀▀
LLBIT▀█ 
  TH#1 SOLANA CASINO  
████████████▄
▀▀██████▀▀███
██▄▄▀▀▄▄████
████████████
██████████
███▀████████
▄▄█████████
████████████
████████████
████████████
████████████
█████████████
████████████▀
████████████▄
▀▀▀▀▀▀▀██████
████████████
███████████
██▄█████████
████▄███████
████████████
█░▀▀████████
▀▀██████████
█████▄█████
████▀▄▀████
▄▄▄▄▄▄▄██████
████████████▀
........5,000+........
GAMES
 
......INSTANT......
WITHDRAWALS
..........HUGE..........
REWARDS
 
............VIP............
PROGRAM
 .
   PLAY NOW    
ImThour
Copper Member
Legendary
*
Offline Offline

Activity: 1498
Merit: 1619


Bitcoin Bottom was at $15.4k


View Profile
February 29, 2024, 01:12:28 PM
 #4

Thanks for sharing however I do not understand the purpose of using these libraries which aren't developed by a guy who understands the security of his own account and is reliable. I never use any library as the code is open source most of the time, you can just copy and paste the function you need from the library instead of completely relying upon it. And nowadays, I use ChatGPT and other AI Programming tools too often to create some interesting snippets or functions.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!