7 ms·
Malicious Python packages replace crypto addresses in developer clipboards
- teddyh 4y ago“At the time of this writing, no funds have been transferred to the attackers.”
- louislang 4y agoWe're trying to stay on top of this as much as possible. I'm hoping if we can be quick to report, the attackers will have wasted a bunch of effort on this campaign and not see a dime.
- paulpauper 4y agoeven giveaway scams on twitter or YouTube which require no coding skills make more than that. it is easier to just pretend to be someone famous and ask people to give you crypto instead, whether for a giveaway, NFT, or a fake project.
- louislang 4y agoAwesome seeing this posted! Full disclosure: I'm a co-founder at Phylum. This campaign is ongoing. Our system just notified us of two more packages, which have been reported to PyPI. I expect this list to continue to grow throughout the day. As a related aside, we are working on a package sandbox that prevents access to disk, network and env variables during package installation. It's not quite ready for primetime, but it is completely open source and we'd love some early feedback/contributions! https://github.com/phylum-dev/birdcage https://github.com/phylum-dev/birdcage If anyone has any questions, I'd be more than happy to answer them!
- eddsh1994 4y agoCool project! Phylum looks useful at addressing a few worries I have with Python. Would it work in a mostly air-gapped environment, or does it have to call home regularly?
- louislang 4y agoWe are basically ingesting and analyzing every package as it gets published to the various ecosystems (currently NPM, PyPI, Rubygems, Maven and Nuget; Go and Crates support landing in beta soon). This is currently offered as a SaaS solution, but we'll be providing an on-prem offering by EOY that should work well in an air-gapped environment. The sandbox I mentioned above is rolled into our CLI by default, but that should operate well enough on its own without needing to call out to our API if you wanted!
- a-dub 4y agointeresting read. i was a bit confused at first, thinking that the malicious package names were being inserted into cut and pasted pip/apt/etc install strings. i see now that's not happening in this scenario, but curious if that behavior has ever been observed.
- louislang 4y agoWe haven't seen this particular sort of thing just yet in packages. There was a similar attack from a few years ago called "pastejacking" that did something directionally similar to what you're suggesting though!
- pabs3 4y agoHow does Phylum detect these issues? I guess you have a mirror of PyPI and run some kind of scanner over all the code?
- anonporridge 4y agoThis is exactly the type of attack many cypherpunk bitcoin types have been paranoid about for years. And it's why in any good hardware wallet, you need to explicitly confirm the address you're transferring to on the wallet's air gapped screen and make sure it wasn't swapped in the copy/paste. I'm sure it would also be quite easy for this kind of attacker to generate thousands of addresses they control, and have their software pick one that looks 'closest' to the one being subverted to increase the likelihood that a lazy user just sanity checks a few characters at the beginning and end of the address before confirming. Survival of the most paranoid.
- louislang 4y agoThere was some discussion of this over on Reddit. I didn't see evidence of it, but the claim was that this had already happened. I'd be curious if someone had some examples of it in the wild.
- throwup 4y agoThis particular clipboard attack has been part of malware for at least 5 years, maybe 10. But I haven't heard of it being distributed via a package manager until now.
- louislang 4y agoOh I meant malware generating addresses that look directionally similar to the address the user expects (as opposed to a random address that's hardcoded). I'm not sure if this is a thing, or just conjecture from others.
- anonporridge 4y agoIt could be very hard to prove after the fact. And it's generally much more likely that human error causes a loss than to be victim to a malicious attack. So even if it has legitimately happened, it's likely to be dismissed as the person was just incompetent and that there just wasn't enough software safeguards to protect people from themselves. This is probably a good lesson in general for intelligent malicious actors. If you have an exploit that works, it's important that you use it rarely enough and against the right marks that the loss doesn't enter the collective consciousness as a malicious attack, but simply as an individual or systemic failure. And for those of us who strive to be constructive and defensive actors, it's an important lesson to remember that sometimes malicious actors disguise their actions as amoral bugs in the system. Regular random auditing of the seemingly mundane is an important tool to uncover these kinds of exploits.
- yunruse 4y agoGiven that these attacks target simple typos on high-download packages, is there no avenue for repositories to implement an “are you sure you want to download this” feature? Some heuristic on the Levenshtein distance and download count, say on the top 100, would go a long way to preventing these kind of attacks. (With some --ignore-typo-suggestion just in case of automated edge-cases, of course :)
- louislang 4y agoThis would be an incredibly useful feature, I think. It was part of the motivation for our sandbox, honestly. It should mostly operate as a pass through the the various package managers - but with some extra security checks. In this way a `phylum npm install <pkgName>` would perform the typosquat checks _and_ limit access to system resources. You can even alias this as `alias npm="phylum npm"` so that it's easier for the user.
- hinkley 4y agoI participated in some Freenet architecture discussions when they were still trying to take the prototype to a practical implementation. There was some talk even back then about how opaque hashes are to the human mind and that we might be better off using phrase mnemonics instead. Particularly useful I would think for transcription errors like this, malicious or accidental. The problem is that the information density of replacing hex with words is quite low, on the order of 14 bits per word, but much longer than the four letters needed to represent 16 bits in hex, which is itself a lot less dense than base64. You’d need 12 words to uniquely identify a sha-1 hash and most modern algorithms are less dense than that. But it would be harder to trick someone. Maybe there’s some sort of 5:4 coding system that’s easier for humans to scan, still to be discovered out there?
- chrisshroba 4y agoI think you may have intended to respond to this comment? [1] [1] https://news.ycombinator.com/item?id=33512203 https://news.ycombinator.com/item?id=33512203
- josephg 4y agoThis is why we need proper sandboxing of applications and libraries. There’s no way tools should be able to silently run any code they want, with my user’s full permissions on my desktop machine. Apps couldn’t get away with this sort of thing on iOS or Android. It’s inconvenient, but we need to raise the bar in the same way for security permissions and sandboxing on the desktop. (But obviously, with the user in control.)
- louislang 4y agoWorking on it! https://github.com/phylum-dev/birdcage https://github.com/phylum-dev/birdcage Allows you to specify the allowed permissions in a toml file. Still a wip, but would love some feedback!
- substation13 4y agoPython package version resolution is a Turing Complete problem and installs are not deterministic. Securing the ecosystem is going to be serious work.
- louislang 4y ago> Securing the ecosystem is going to be serious work Oh it _absolutely_ is! We're working extremely hard here and I think we're making great strides. More hard work to come, but I think it's absolutely worth the effort!
- xigoi 4y agohttps://www.splitgraph.com/blog/poetry-dependency-resolver-sudoku https://www.splitgraph.com/blog/poetry-dependency-resolver-s...
- louislang 4y agoThis is wonderfully absurd in the best sort of way
- BlueTemplar 4y agoSomewhat ironically, the article won't even show up unless I allow content from a 3rd party website : unpkg.com
- ForHackernews 4y agoBe your own bank IT security department!
- lifeisstillgood 4y agoAt some point we need to give up on "everyone can run their home security better than the CIA room Tom Cruise abseiled into". If every time I wanted to pay for a coffee I was risking losing all my savings, then I (and millions of others) would go back to cash I am not sure where that leaves us for "digital native cash". Perhaps phones and secure enclaves will save us, perhaps we just have to pay the Visa tax.
- louislang 4y agoAbsolutely don't disagree with this sentiment. The fact of the matter is the attackers only have to be "right" once. Whereas the rest of us have to be right hundreds or thousands of times. If it's a numbers game, the odds are definitely in favor of the attackers. Cryptocurrency aside, it definitely looks like these attacks are ramping up and we - the developers with access to critical infrastructure - are the primary targets. Today its crypto, tomorrow it's SSH keys. It's both worrisome and tremendously annoying.
- lifeisstillgood 4y agoYeah that point about SSH keys just worried me. The keys to pretty much every online kingdom are only 2048 bits long and once the methods to exfiltrate crypto have been honed it's worth looking at ways to weaponise the others.
- pvg 4y agoPrevious thread 5 days ago, 325 comments https://news.ycombinator.com/item?id=33438678 https://news.ycombinator.com/item?id=33438678
- louislang 4y agoThat’s a different, unrelated campaign!
- dang 4y agoI believe you, but the overall story is similar enough that the current one probably doesn't count as significant new information (https://hn.algolia.com/?dateRange=all&page=0&prefix=false&sort=byDate&type=comment&query=%22significant%20new%20information%22%20by%3Adang https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...). HN thrives on differences, and repetition (even if it isn't exact repetition) tends to reduce the interest of a submission.
- louislang 4y agoThat's fair, thanks for the feedback!
- deleted 4y ago[deleted]