ThreatMon Blog
  • Platform
  • Intelligence Modules
    • Cyber Threat Intelligence
    • Attack Surface Management
    • Digital Risk Protection
  • Resources
    • Blog
    • Reports
  • Company
    • About Us
    • Term & Use
    • Privacy Policy
  • Platform
  • Intelligence Modules
    • Cyber Threat Intelligence
    • Attack Surface Management
    • Digital Risk Protection
  • Resources
    • Blog
    • Reports
  • Company
    • About Us
    • Term & Use
    • Privacy Policy
No Result
View All Result
ThreatMon Blog
No Result
View All Result

Home » PyPI Package ‘secretslib’ Drops Fileless Cryptominer to Linux Systems

PyPI Package ‘secretslib’ Drops Fileless Cryptominer to Linux Systems

A budget tells us what we can't afford, but it doesn't keep us from buying it.

ibrahim mestav by ibrahim mestav
August 5, 2023
in Security News
0
pypi-package-secretslib-drops-fileless-cryptominer-to-linux-systems
597
SHARES
3.3k
VIEWS
Share on FacebookShare on Twitter

PyPI Package ‘secretslib’ Drops Fileless Cryptominer to Linux Systems

A PyPI package named “secretslib” has been identified by Sonatype, which describes itself as “secret mapping and verification made easy”. The package secretly runs cryptominers in the memory of the Linux machine, a technique largely used by fileless malware and cryptominers. Secretslib was downloaded 93 times before it was deleted.

The threat actor that released the malicious package used the identity and contact details of a genuine national lab software engineer in a US Department of Energy-funded lab to give credibility to their malware.

Sonatype’s automated malware detection systems, available as part of the Nexus Firewall, flagged the ‘secretslib’ PyPI package as potentially malicious.

At the time of release, the package looked like a library that helped match and validate secrets.

secretslib

The threat actor does this by executing a post-installation Linux executable from a remote server, whose main task is to act as a Monero cryptominer and then directly drop an ELF file (“memfd”) into memory that is deleted by the “secretslib” package.

The goal is to trick users into downloading toxic libraries by assigning them to trusted, popular maintainers without their knowledge or approval.

References:

https://blog.sonatype.com/pypi-package-secretslib-drops-fileless-linux-malware-to-mine-monero

Previous Post

Microsoft Has Disrupted SEABORGIUM’s Ongoing Phishing Operation

Next Post

USA Offers $10M Bounty for Providing Information on the Conti Ransomware Gang

Next Post
usa-offers-10m-bounty-for-providing-information-on-the-conti-ransomware-gang

USA Offers $10M Bounty for Providing Information on the Conti Ransomware Gang

Recommended

usa-offers-10m-bounty-for-providing-information-on-the-conti-ransomware-gang

USA Offers $10M Bounty for Providing Information on the Conti Ransomware Gang

August 5, 2023
what-is-cyber-threat

What is “Cyber Threat”?

September 7, 2023

Popular Story

  • chatgpt-and-malware-analysis-threatmon

    ChatGPT and Malware Analysis – ThreatMon

    977 shares
    Share 391 Tweet 244
  • ChatGPT and Cyber Security in 15 Questions: Impacts, Benefits and Harms

    777 shares
    Share 311 Tweet 194
  • TA558 APT Group Uses Malicious Microsoft Compiled HTML Help Files

    751 shares
    Share 300 Tweet 188
  • What is SMTP Open Mail Relay Vulnerability?

    727 shares
    Share 291 Tweet 182
  • The Importance of Attack Surface Management for Organizations

    678 shares
    Share 271 Tweet 170

Intelligence Modules

Cyber Threat Intelligence Attack Surface Management Digital Risk Protection

Resources

Blog Reports

Platform

Discover the platform

Company

About Us Terms & Use Privacy Policy

Blog

The Importance of Attack Surface Management for Organizations ChatGPT and Malware Analysis – ThreatMon TA558 APT Group Uses Malicious Microsoft Compiled HTML Help Files
threatmon-logo

Copyright © 2023

No Result
View All Result
  • Platform
  • Intelligence Modules
    • Cyber Threat Intelligence
    • Attack Surface Management
    • Digital Risk Protection
  • Resources
    • Blog
    • Reports
  • Company
    • About Us
    • Term & Use
    • Privacy Policy

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Advanced Threat Intelligence Platform
Get 30 Days Free Trial
Get 30 Days Free Trial