Some were targeting developers familiar with the loglib and pyg libraries
(Image credit: Shutterstock)
Multiple malicious Python packages leaking sensitive user information have been uncovered by security experts.
In a blog post (opens in new tab), Sonatype security researcher Ax Sharma says the packages: loglib-modules, pyg-modules, pygrata, pygrata-utils, and hkg-sol-utils, were exfiltrating people’s secrets, such as AWS credentials and environment variables, and uploading them to a publicly exposed endpoint (opens in new tab).
Some, as their names would suggest, were targeting developers familiar with the loglib and pyg libraries, while others have unknown targets.
Unknown attackers
We don’t know exactly how many people have had their data exposed (opens in new tab), although Sharma said the researchers found “hundreds of TXT files containing sensitive information and secrets”.
To rule out the possibility of a security team doing research, Sonatype reached out to the owners of pygrata[.]com but never heard back. Soon after, the endpoint that was leaking the TXT files timed out, which made the researchers think someone must have shut it down. Furthermore, loglib-modules was quickly pulled from the web, albeit briefly.
Sonatype did not manage to discover who the threat actor behind the attack is, or what their ultimate goal was.
Read more
> This dangerous Android banking trojan is now available online for anyone to use (opens in new tab)
> One of the most fearsome Android trojans around just got even nastier (opens in new tab)
> New Trojan malware steals millions of login credentials (opens in new tab)
“Were the stolen credentials being intentionally exposed on the web (opens in new tab) or a consequence of poor opsec practices?”, Sharma asks. “Should this be some kind of legitimate security testing, there surely isn’t much information at this time to rule out the suspicious nature of this activity.”
Soon after reporting all of the problematic packages to the PyPI security team, they were all taken down, the company concluded.
Every now and then researchers discover malicious packages on open source repositories. Earlier this year, researchers found two Python and PHP packages (ctx and phpass), which essentially worked like trojans. It was later discovered that a Turkish security researcher Yunus Aydin was behind the two packages, as a demonstration of “how this simple attack affects +10M users and companies.”
Computing
News Related
-
-
Cupra’s Leon shares many elements with the Volkswagen Golf. What we like Attention-grabbing design Sporty dynamics Three-years free servicing What we don’t Touch-only multimedia system Ride can be a tad harsh Shift paddle selector is inferior to a traditional shifter What we like Attention-grabbing design Sporty dynamics Three-years free servicing ...
See Details:
Cupra Leon 2023 review
-
Cupra’s Formentor is available in four different engine configurations. What we like Style in spades Surprisingly practical Supportive sports seats What we don’t Multimedia system is finnicky Spotty wireless Android Auto connection Aesthetics won’t suit conservative tastes What we like Style in spades Surprisingly practical Supportive sports seats What we ...
See Details:
Cupra Formentor 2023 review
-
-
After a lot of “hoo-ha,” Nothing finally released its first smartphone, the phone (1) with a different and attractive semi-transparent design. And now a month later, the phone received its first price hike in India. Here’s a look at the new prices. Nothing phone (1) New Price in India The ...
See Details:
Nothing Phone (1) Gets a Price Hike Just a Month After Its Launch
-
Today, CIMB Bank Berhad and CIMB Islamic Bank Berhad introduced the early release of the CIMB OCTO App. Although it’s still in the early stages, CIMB customers can now start using it and provide their feedback before the app’s full release. Like other similar banking apps, CIMB said the OCTO ...
See Details:
CIMB launches CIMB OCTO App, now available to download as early release
-
Prior to the launch of the front-wheel drive BMW 2 Series Active Tourer, BMW was known as a marque that primarily built rear-wheel drive cars. The 2 Series Active Tourer was first launched in 2014, and a seven-seater Gran Tourer, as featured, was added to the line-up in 2015. These ...
See Details:
Motorist Car Buyer's Guide: BMW 216i Gran Tourer M-Sport
-
Toyota’s sporty Camry is no longer available with a V6. That said, the SX hybrid’s sporty suspension performs better than expected with a fuel-sipping powertrain
See Details:
Toyota Camry SX hybrid 2022 review
-
Toyota’s sporty Camry is no longer available with a V6. That said, the SX hybrid’s sporty suspension performs better than expected with a fuel-sipping powertrain
See Details:
Kia Niro Hybrid GT-Line 2022 review
-
Toyota’s sporty Camry is no longer available with a V6. That said, the SX hybrid’s sporty suspension performs better than expected with a fuel-sipping powertrain
See Details:
Honda CR-V VTi X 2022 review
-
-
-
-
OTHER NEWS
Today, U Mobile is excited to unveil two new postpaid plans – the U Postpaid 98 and U Postpaid 68 to join the U Postpaid 38 which was launched earlier. ...
Read more »
This is the sweet spot of the popular SUV’s extensive range
Read more »
Realme has recently launched the 5G version of the Realme 9i. The 4G variant of the smartphone was launched at the beginning of the year. In terms of design, Realme ...
Read more »
Maruti Suzuki has launched a 2022 Alto K10 edition in India with major upgrades to the powertrain and features. The 2022 Maruti Suzuki Alto K10 has made a comeback with ...
Read more »
The gaming giant has announced a fresh wave of game-related acquisitions, including physical game specialist Limited Run Games.
Read more »
As we learned in our article on Jio’s 5G network in India, Reliance Jio is all set to revolutionize mobile connectivity in India again. Not just that, the company is ...
Read more »
As expected, Realme has introduced the new Realme 9i 5G budget phone in India. This is yet another member of the Realme 9 series and happens to be the 5G ...
Read more »
With the 5G launch in India right around the corner, Realme is betting big on affordability with the Realme 9i 5G. But is that enough to lure the buyers? Find out in our review.
Read more »
If you ever watched a classic Godzilla film and thought to yourself that the King of Monsters could use a lot more romance in his kaiju life, well, do we ...
Read more »
HP and SkillsFuture Singapore (SSG) have announced the SkillsFuture Queen Bee partnership to support local manufacturing companies in sustainable manufacturing. As part of this, HP and SIM have co-developed 15 ...
Read more »
With most of its competition discontinued, Alto K10 has very few rivals left to compete with 2022 Maruti Alto K10 Launched Maruti Suzuki has been a long-standing champion in A-segment ...
Read more »
The money you invested into the pricy virtual-reality headsets needs to mean something. So, now that you’re here join us and check the best 20 PSVR games in 2022. VR ...
Read more »
Discord is a free-to-use application where anyone can sign up and get going. Similarly, users can subscribe to Discord Nitro to move a notch up and get additional features. But, ...
Read more »
There’s plenty you can do on the Nintendo Switch without an internet connection, but the lack of one creates a real problem even in games that aren’t online. The internet ...
Read more »
The Phone (1) will go on sale again on August 22nd.
Read more »
A mousepad is not just an accessory to complete your PC setup. It also allows the mouse to have smooth movement. Without a mouse pad, the mouse cursor may have ...
Read more »
If you're currently on the fence about buying a Nintendo Switch, the latest update from the Japanese gaming giant suggests that it should be fine for you to start crunching ...
Read more »
Back in June 2022, Netflix confirmed that there would be an ad-supported tier for viewers looking to pay less and don’t mind advertising. Now, it looks like advertisements aren’t the ...
Read more »
It is possible that the contents on your phone or computer may accidentally get erased or corrupted. So, uploading them to Google Drive will ensure safety and flexibility to access ...
Read more »
Voicemail is a handy feature that lets you record a voice message if the other person fails to receive the call on time. However, sometimes you can’t access this feature ...
Read more »
Apple’s AirPods have a compact and portable design. In a lot of ways, this comes in handy. But the design also increases the likelihood of it getting lost. Luckily, Apple ...
Read more »
Today Genshin Impact developer released a new trailer showcasing a new character coming to the game, Tighnari. Tighnari is a ranger wielding a bow and the power of the new ...
Read more »
Whenever an application freezes or the system become unresponsive, you can use task manager to terminate its processes to get out of the troublesome situation. But if the task manager ...
Read more »
While playing Minecraft, you may probably get the error message ‘You need to authenticate to Microsoft services.’ It normally occurs when you try to access external servers or personal multiplayer ...
Read more »
“Copying update file” or “Queued for copy” are messages that halt game downloads and updates. Under the wrong conditions, it halts your gaming altogether. So, why does copying takes so ...
Read more »
The VMware Fusion application on a Mac computer is designed to run another operating system simultaneously with the macOS. This virtualized OS can then be used in a manner similar ...
Read more »
The gaming giant has added Tolkien's works of Middle-earth to its roster, acquiring the rights to produce films, video games, board games, and more.
Read more »
The Realme 9i 5G is priced under Rs 15,000 and will be available via Flipkart.
Read more »
At a starting price of Rs. 15,999 the Moto Tab G62 goes up against the Realme Pad Mini and OPPO Pad Air, what does it do differently to stand out in the market?
Read more »
No thanks to the Covid-19 pandemic, the past two years have been a detriment to fan conventions around the world, but with things looking up in 2022, more and more ...
Read more »
BSOD Page fault in the nonpaged area is the error code that you receive during the dreaded blue screen of death. It is a critical error related to your memory. ...
Read more »
When you see a blinking orange light on your XFINITY router, it means there’s a firmware upgrade processing. It could be downloading the update to the router or installing it. ...
Read more »
Time flies when you’re streaming on HBO Max. Its vast library with an impressive selection of movies and TV shows ensures that you never run out of content to watch. ...
Read more »
Telcos have already started deploying their 5G services, and the union IT minister suggests the first rollouts to take place by October.
Read more »
An official confirmation is yet to be made regarding Death Stranding on PC Game Pass.
Read more »
With growing subscribers of YouTube worldwide, it has also been very popular among kids. It is more likely that the children are inclined toward YouTube addiction. We all have a ...
Read more »
Apple is prepping up to hold a launch event on September 7 for the release of the much-awaited iPhone 14 line-up. Furthermore, it is also being said that the audience ...
Read more »
Hyundai’s N Line special edition versions get minor mechanical upgrades and are not just a styling exercise 2022 Hyundai Venue N Line After the launch of its flagship Tucson SUV ...
Read more »
Today is financial results day for growing gaming giant Embracer, and if you’ve paid attention, you know what that means. They also announced a large bunch of acquisitions. The list ...
Read more »
Microsoft Word has a built-in feature to convert its DOC file to PDF. The PDF file is a generally accepted file format to present or share a document. If you ...
Read more »