#PyPI

Malware/Tool

2023-08-03 • VMConnect: Malicious PyPI packages imitate popular open source modules

PyPI is the legitimate Python Package Index, not malware. Threat actors abuse the repository to distribute poisoned or impersonating packages, sometimes coordinating releases across npm, Go Modules, crates.io, and Packagist. DPRK-linked Contagious Interview and PolinRider campaigns used malicious Python packages, shared loader infrastructure, platform-specific second stages, information stealers, and remote-access Trojans. Reported package names included logutilkit, apachelicense, fluxhttp, and license-utils-kit. Repository telemetry also showed rapid growth in PyPI threat records, reflecting PyPI’s role as a software-supply-chain delivery channel rather than a malicious program.

Tagged Reports

« Back