BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious PyPI Packages Uncovered: Supply Chain Risk for Python

Malicious Python and npm Packages Expose Software Supply Chains to Remote Code Execution and Data Theft

  • Researchers identified malicious Python and npm packages facilitating Malware attacks through official repositories.
  • The compromised Python packages, termncolor and colorinal, enabled remote code execution and system persistence on both Windows and Linux.
  • Attackers used DLL side-loading and registry manipulation to maintain access and stole information using the Zulip chat app.
  • Similar threats in npm packages targeted developers and security researchers, aiming to steal sensitive data and credentials.
  • Reports highlighted risks from automatic dependency upgrades, as seen in a recent compromise of the eslint-config-prettier npm package.

Cybersecurity researchers have found harmful software in the official Python Package Index (PyPI) and npm package repositories, putting software supply chains at risk. The packages, called termncolor and its dependency colorinal, were discovered after being downloaded hundreds of times before removal from PyPI.

- Advertisement -

According to Zscaler ThreatLabz, the termncolor package imported colorinal, which triggered a multi-stage malware process. These stages involved loading a fake dynamic-link library (DLL) file to decrypt further malware. The operation allowed attackers to silently keep access to computers and run remote code.

The researchers, Manisha Ramcharan Prajapati and Satyam Singh, explained that this attack used DLL side-loading to decrypt, maintain system persistence, and conduct command-and-control (C2) communication. “Persistence is achieved by creating a registry entry under the Windows Run key to ensure automatic execution of the malware at system startup,” Zscaler said. On Linux systems, the attack involved a shared object file called terminate.so to deliver similar effects.

Zscaler noted the attackers hid their activities by using Zulip, an open-source chat app, for C2 traffic. Analysis showed three active users and nearly 91,000 messages exchanged. The malware author has reportedly been active since July 10, 2025. Zscaler pointed out, “The termncolor package and its malicious dependency colorinal highlight the importance of monitoring open-source ecosystems for potential supply chain attacks.”

Separate findings from SlowMist revealed that some threat actors are tricking developers by posing as job recruiters and asking them to run infected npm packages. The discovered npm packages, such as redux-ace and rtk-logger, secretly stole keychain, browser, and cryptocurrency wallet data by running Python scripts and gathering private information.

- Advertisement -

Other recent cases included attackers targeting cybersecurity professionals using poisoned npm packages promoted as fake security tools or code patches. Datadog researchers connected this strategy to a group tracked as MUT-1244.

Further highlighting the risks, ReversingLabs reported on the compromise of the eslint-config-prettier npm package through a phishing attack. This impacted more than 14,000 projects that listed the package as a regular dependency, which led automated tools like Dependabot to update them without manual checks. Researcher Karlo Zanki stated that such tools, while meant to reduce risk, can also introduce new security problems if not properly configured.

These incidents underline the need for ongoing monitoring of open-source software repositories and careful review of package dependencies.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Sonic V2.2 doubles smart contract size limits for developers

Sonic V2.2 doubles the maximum deployed contract size from 24 KiB to 48 KiB...

ByteDance Secures $29.6B Loan from 30 Banks for AI Push

TikTok parent ByteDance secured a $29.6 billion loan from nearly 30 Chinese and international...

Musk: Tesla IPO value was a thousandth of current value

Tesla stock fell roughly 6% on Friday after the Cybercab launch event in Austin...

Tesla Cybercab stock crashes 6% on NHTSA audit

Tesla stock dropped 6% in an hour after the NHTSA opened a compliance audit...

Pineapple moves $1B mortgage records onto Injective blockchain

Pineapple Financial has migrated over $1 billion in residential mortgage records onto Injective, with...

Must Read

Top 8 Books Every Beginner Should Read About Cryptocurrency

Cryptocurrency and blockchain technology are filled with technical terms that beginners find challenging to understand. One of the best ways to learn about cryptocurrency...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading