Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Malicious PyPI Package Installs Monero Cryptominer on Linux Systems

32.Lock Code Circular Esm H446

A malicious PyPI package was used to install a Monero cryptominer on Linux systems.

 

The package in question, secretslib, was pushed to the official third-party software repo for Python on 6th August 2022. The package was described as “secrets matching and verification made easy”.

Sonatype’s automated malware detection system flagged secretslib as potentially malicious. Further analysis proved its suspicions to be correct.

The link for this article located at Developer is no longer available.

Your message here