dubbel,
@dubbel@mstdn.io avatar

Reported 15 malicious #PyPI packages: asyncioo, asyyncio, asyincio, aasyncio, etc...

On install they decrypt Fernet encrypted code, which loads further code from https://funcaptcha[.]ru/paste2?package=asyncioo (replace the parameter with the package name).

I was blocked from accessing that code (am on mobile right now, so I don't have the means to investigate for real, Fernet decryption was already fun :abloblamp: ).

Anyone else able to access it?

#IOC #threatIntel #python

  • All
  • Subscribed
  • Moderated
  • Favorites
  • python
  • DreamBathrooms
  • magazineikmin
  • InstantRegret
  • ethstaker
  • cubers
  • rosin
  • Youngstown
  • slotface
  • everett
  • osvaldo12
  • kavyap
  • khanakhh
  • mdbf
  • ngwrru68w68
  • megavids
  • thenastyranch
  • normalnudes
  • cisconetworking
  • love
  • GTA5RPClips
  • Durango
  • tacticalgear
  • modclub
  • anitta
  • Leos
  • tester
  • provamag3
  • JUstTest
  • All magazines