CyberSecurity news

FlagThis - #Python

info@thehackernews.com (The Hacker News)@The Hacker News //
PyPI (Python Package Index) has launched a new 'Project Archival' feature, empowering maintainers to mark projects as archived. This signals to users that these projects are no longer actively maintained or expected to receive updates, including crucial security fixes. While archived projects remain installable, the new status alerts developers to the risk of relying on unmaintained packages, thereby promoting more responsible dependency management. Maintainers can archive projects via their settings page on PyPI, prompting a prominent notice to appear on the project's main page.

The new archival system seeks to improve supply chain security by explicitly communicating the maintenance status of projects. This builds on PyPI's existing "project quarantine" framework introduced in late 2024, which allows administrators to mark suspicious projects and prevent their installation. By enabling maintainers to clearly denote the state of archived projects, this feature enhances visibility into the lifecycle of packages. PyPI recommends that package developers release a final version before archiving, including a detailed update in the project description to provide additional context about its status.

The archival process is reversible, giving project owners the option to resume maintenance if desired. As part of broader efforts to enhance project lifecycle management within PyPI, further project status labels such as "deprecated" or "unmaintained" may be introduced, along with updates to PyPI's public APIs to allow for easier retrieval of project status information. The goal is to provide a more structured and informative ecosystem for Python developers.

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • gbhackers.com: This website contains the latest news about cybersecurity incidents and attacks.
  • The Hacker News: This website contains the latest news about cybersecurity incidents and attacks.
  • www.bleepingcomputer.com: This website contains the latest news about cybersecurity incidents and attacks.
  • gbhackers.com: The Python Package Index (PyPI) has introduced a new feature that allows maintainers to mark projects as archived, signaling that the project is no longer actively maintained or expected to receive updates.
  • BleepingComputer: The Python Package Index (PyPI) has announced the introduction of 'Project Archival,' a new system that allows publishers to archive their projects, indicating to the users that no updates are to be expected.
  • ciso2ciso.com: PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages – Source:thehackernews.com
  • cyberpress.org: PyPI Implements Project Archival to Block Exploits Malicious Package
  • Cyber Security News: PyPI Implements Project Archival to Block Exploits Malicious Package
  • blog.pypi.org: Trail of Bits: PyPI Now Supports Project Archival More: The Hacker News: PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages
  • ciso2ciso.com: PyPI Introduces Archival Status to Alert Users About Unmaintained Python Packages – Source:thehackernews.com
  • www.cysecurity.news: PyPI's New Archival Feature Addresses a Major Security Flaw
  • Help Net Security: DeepSeek’s popularity exploited to push malicious packages via PyPI
Classification:
Samarth Mishra@cysecurity.news //
A malicious Python package named 'set-utils' has been discovered on the Python Package Index (PyPI) repository. This package is designed to steal Ethereum private keys by exploiting commonly used account creation functions. Disguised as a utility for Python sets, the package mimics popular libraries, tricking developers into installing it. Since its appearance, 'set-utils' has been downloaded over 1,000 times, posing a significant threat to Ethereum users and developers, particularly those working with Python-based wallet management libraries. The Python security team has removed the malicious package from PyPI.

The 'set-utils' package operates by silently modifying standard Ethereum wallet creation functions. The private keys are exfiltrated within blockchain transactions via the Polygon RPC endpoint to resist traditional detection efforts. The stolen keys are encrypted using an attacker-controlled RSA public key before transmission, making detection challenging. Even if the package is uninstalled, any Ethereum wallets created while it was active remain compromised. To mitigate these risks, developers should employ regular dependency audits and automated scanning tools to detect malicious behaviors in third-party packages.

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • The Hacker News: Cybersecurity researchers have discovered a malicious Python package on the Python Package Index (PyPI) repository that's equipped to steal a victim's Ethereum private keys by impersonating popular libraries.
  • Developer Tech News: A malicious package designed to steal private keys for Ethereum wallets has been uncovered within the Python Package Index (PyPI). According to Socket, this package – named ‘set-utils’ – masquerades as a utility for Python sets and has been actively targeting developers.
  • Cyber Security News: PyPI Malware Exploits Developers to Hijack Ethereum Wallets
  • gbhackers.com: New PyPI Malware Targets Developers to Steal Ethereum Wallets
  • www.cysecurity.news: Researchers at have exposed a malicious PyPi (Python Package Index package), set-utils, that steals Ethereum private keys by abusing a “commonly used account creation functions.â€�
Classification:
  • HashTags: #Ethereum #PyPI #Malware
  • Company: Python
  • Target: Ethereum Developers
  • Product: set-utils
  • Feature: Private Key Theft
  • Malware: set-utils
  • Type: Malware
  • Severity: Major
MalBot@malware.news //

Share: bluesky twitterx--v2 facebook--v1 threads


References :
  • The Hacker News: The Hacker News reports on researchers uncovering PyPI packages stealing keystrokes and hijacking social accounts.
  • Techzine Global: Two malicious Python packages revealed by FortiGuard Labs
  • ciso2ciso.com: Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data – Source:hackread.com
  • ciso2ciso.com: Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data – Source:hackread.com
  • osint10x.com: Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts
  • securityonline.info: PyPI Poisoned: “Zebo” and “Cometlogger” Downloaded Hundreds of Times
Classification: