VMConnect: Malicious PyPI packages imitate popular open source modules

2023-08-03 Reversing Labs

https://www.reversinglabs.com/blog/vmconnect-malicious-pypi-packages-imitate-popular-open-source-modules

Thumbnail for VMConnect: Malicious PyPI packages imitate popular open source modules

ReversingLabs identified the VMConnect PyPI supply-chain campaign, in which 24 malicious packages impersonated popular Python modules such as vConnector, eth-tester, and databases while publishing linked GitHub projects that omitted the malicious code. The packages implemented enough legitimate functionality to deceive developers, but VMConnect’s __init__.py decoded and executed Base64-obfuscated code in a separate process. The payload built a host-specific C2 URL, repeatedly polled the live server for additional Base64-encoded commands, and could execute follow-on code if the operator selected the host. The campaign shows a more deliberate open-source repository abuse pattern than simple typosquatting because the malicious PyPI releases were paired with benign-looking project infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dbc14c3ac0528a8aeb6edba8a0b2792… 2023-08-03 2023-10-24
HASH 9a276ca3678898f5596166416f7e709… 2023-08-03 2023-10-24
HASH 67226da423ab4a2c97b2d008dec4528… 2023-08-03 2023-10-24
HASH 0b7b4444f820e9990dfeb5e2080321b… 2023-08-03 2023-10-24
HASH 0eb79e80c51c0e14be3620dfb237f7b… 2023-08-03 2023-10-24
HASH 0dc723e77a5b97183a90eaecb62c9b7… 2023-08-03 2023-10-24
HASH 2ff1b3aa2dbff6d87447b250a8d1924… 2023-08-03 2023-10-24
HASH e531121b137182453f0d120be860ad8… 2023-08-03 2023-10-24
HASH 9588affaf9d85e2141b9d76b914d9f8… 2023-08-03 2023-10-24
HASH de4e9efeace6ff76dc00a166dca152d… 2023-08-03 2023-10-24
HASH b1f2d50be0aca0672475488d77c6f71… 2023-08-03 2023-10-24
HASH 664f0913a5952eeb77373f83e090fab… 2023-08-03 2023-10-24
HASH bc2d48d6d9eeaf0b29625683942e90d… 2023-08-03 2023-10-24
HASH d404a55f1f7fbcd8b3156a84ebcf97c… 2023-08-03 2023-10-24
HASH 19684554e4905bb3cf354a5d5a0f00d… 2023-08-03 2023-10-24
HASH bd7ba47f730c2bc33afa67a39d9cbe3… 2023-08-03 2023-10-24
HASH 658605988c7afd9adf437fb64ff682c… 2023-08-03 2023-10-24
HASH 6bf76b01bd17f370cd3f9947135bf25… 2023-08-03 2023-10-24
HASH a1b039f88c385f5c5eec2ef1701251c… 2023-08-03 2023-10-24
HASH 5f03b73d56528ecbc3f24b8e7daec6b… 2023-08-03 2023-10-24
HASH 146942c5dbaba55be174b1bfb127410… 2023-08-03 2023-10-24
HASH 497df2fd2dba324be04cc57f50a3170… 2023-08-03 2023-10-24
HASH e6494b9a91862191556d77022e5577d… 2023-08-03 2023-10-24
HASH b0095f149951241c6e11e0d1be1f74e… 2023-08-03 2023-10-24
DOMAIN deliworkshopexpress.xyz 2023-08-03 2023-10-24
IPv4 45.61.139.219 2023-08-03 2023-10-24

Related Reports

« Back