• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
malicious pypi package 'fabrice' found stealing aws keys from thousands

Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers

You are here: Home / General Cyber Security News / Malicious PyPI Package ‘Fabrice’ Found Stealing AWS Keys from Thousands of Developers
November 7, 2024

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) that has racked up thousands of downloads for over three years while stealthily exfiltrating developers’ Amazon Web Services (AWS) credentials.

The package in question is “fabrice,” which typosquats a popular Python library known as “fabric,” which is designed to execute shell commands remotely over SSH.

While the legitimate package has over 202 million downloads, its malicious counterpart has been downloaded more than 37,100 times to date. As of writing, “fabrice” is still available for download from PyPI. It was first published in March 2021.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

The typosquatting package is designed to exploit the trust associated with “fabric,” incorporating “payloads that steal credentials, create backdoors, and execute platform-specific scripts,” security firm Socket said.

“Fabrice” is designed to carry out its malicious actions based on the operating system on which it’s installed. On Linux machines, it uses a specific function to download, decode, and execute four different shell scripts from an external server (“89.44.9[.]227”).

On systems running Windows, two different payloads – a Visual Basic Script (“p.vbs”) and a Python script – are extracted and executed, with the former running a hidden Python script (“d.py”) stored in the Downloads folder.

“This VBScript functions as a launcher, allowing the Python script to execute commands or initiate further payloads as designed by the attacker,” security researchers Dhanesh Dodia, Sambarathi Sai, and Dwijay Chintakunta said.

The other Python script is designed to download a malicious executable from the same remote server, save it as “chrome.exe” in the Downloads folder, set up persistence using scheduled tasks to run the binary every 15 minutes, and finally delete the “d.py” file.

Cybersecurity

The end goal of the package, regardless of the operating system, appears to be credential theft, gathering AWS access and secret keys using the Boto3 AWS Software Development Kit (SDK) for Python and exfiltrating the information back to the server.

“By collecting AWS keys, the attacker gains access to potentially sensitive cloud resources,” the researchers said. “The fabrice package represents a sophisticated typosquatting attack, crafted to impersonate the trusted fabric library and exploit unsuspecting developers by gaining unauthorized access to sensitive credentials on both Linux and Windows systems.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «cisco releases patch for critical urwb vulnerability in industrial wireless Cisco Releases Patch for Critical URWB Vulnerability in Industrial Wireless Systems
Next Post: China-Aligned MirrorFace Hackers Target EU Diplomats with World Expo 2025 Bait china aligned mirrorface hackers target eu diplomats with world expo 2025»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.