• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
dormant pypi package compromised to spread nova sentinel malware

Dormant PyPI Package Compromised to Spread Nova Sentinel Malware

You are here: Home / General Cyber Security News / Dormant PyPI Package Compromised to Spread Nova Sentinel Malware
February 23, 2024

A dormant bundle offered on the Python Deal Index (PyPI) repository was current just about after two years to propagate an info stealer malware termed Nova Sentinel.

The deal, named django-log-tracker, was initially revealed to PyPI in April 2022, according to software package offer chain security business Phylum, which detected an anomalous update to the library on February 21, 2024.

When the connected GitHub repository hasn’t been up to date considering the fact that April 10, 2022, the introduction of a destructive update implies a probable compromise of the PyPI account belonging to the developer.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Django-log-tracker has been downloaded 3,866 moments to date, with the rogue variation (1..4) downloaded 107 moments on the day it was revealed. The package deal is no extended available for download from PyPI.

Cybersecurity

“In the malicious update, the attacker stripped the package of most of its initial information, leaving only an __init__.py and illustration.py file at the rear of,” the business mentioned.

The variations, easy and self-explanatory, involve fetching an executable named “Updater_1.4.4_x64.exe” from a distant server (“45.88.180[.]54”), followed by launching it working with the Python os.startfile() functionality.

The binary, for its section, comes embedded with Nova Sentinel, a stealer malware that was 1st documented by Sekoia in November 2023 as remaining dispersed in the sort of bogus Electron apps on bogus websites offering online video recreation downloads.

“What is intriguing about this specific situation […] is that the attack vector appeared to be an attempted provide-chain attack via a compromised PyPI account,” Phylum explained.

“If this experienced been a definitely well-liked package, any challenge with this offer outlined as a dependency with out a edition specified or a versatile variation specified in their dependency file would have pulled the latest, destructive edition of this package.”

Found this write-up attention-grabbing? Stick to us on Twitter  and LinkedIn to examine much more exceptional material we post.


Some parts of this post are sourced from:
thehackernews.com

Previous Post: «microsoft releases pyrit a red teaming tool for generative Microsoft Releases PyRIT – A Red Teaming Tool for Generative AI
Next Post: Microsoft Expands Free Logging Capabilities for all U.S. Federal Agencies microsoft expands free logging capabilities for all u.s. federal agencies»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.