By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials
Tech News

Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials

By Viral Trending Content 3 Min Read
Share
SHARE

Jul 27, 2024NewsroomCybersecurity / Cloud Security

Malicious PyPI Package

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that targets Apple macOS systems with the goal of stealing users’ Google Cloud credentials from a narrow pool of victims.

The package, named “lr-utils-lib,” attracted a total of 59 downloads before it was taken down. It was uploaded to the registry in early June 2024.

“The malware uses a list of predefined hashes to target specific macOS machines and attempts to harvest Google Cloud authentication data,” Checkmarx researcher Yehuda Gelb said in a Friday report. “The harvested credentials are sent to a remote server.”

Cybersecurity

An important aspect of the package is that it first checks if it has been installed on a macOS system, and only then proceeds to compare the system’s Universally Unique Identifier (UUID) against a hard-coded list of 64 hashes.

If the compromised machine is among those specified in the predefined set, it attempts to access two files, namely application_default_credentials.json and credentials.db, located in the ~/.config/gcloud directory, which contain Google Cloud authentication data.

Malicious PyPI Package

The captured information is then transmitted over HTTP to a remote server “europe-west2-workload-422915[.]cloudfunctions[.]net.”

Checkmarx said it also found a fake profile on LinkedIn with the name “Lucid Zenith” that matched the package’s owner and falsely claimed to be the CEO of Apex Companies, suggesting a possible social engineering element to the attack.

Exactly who is behind the campaign is currently not known. However, it comes more than two months after cybersecurity firm Phylum disclosed details of another supply chain attack involving a Python package called “requests-darwin-lite” that was also found to unleash its malicious actions after checking the UUID of the macOS host.

These campaigns are a sign that threat actors have prior knowledge of the macOS systems they want to infiltrate and are going to great lengths to ensure that the malicious packages are distributed only to those particular machines.

It also speaks to the tactics malicious actors employ to distribute lookalike packages, aiming to deceive developers into incorporating them into their applications.

“While it is not clear whether this attack targeted individuals or enterprises, these kinds of attacks can significantly impact enterprises,” Gelb said. “While the initial compromise usually occurs on an individual developer’s machine, the implications for enterprises can be substantial.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Trump Takes Aim at State AI Laws in Draft Executive Order

Changing Ends Season 3 Review: Forget Alan Carr’s The Traitors Success

1,139 HP: The New Porsche Cayenne Electric is a Monster

Former Revolut executives raise €30M to bring blockchain-based banking app Deblock to Ireland

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

TAGGED: Cloud security, Credential Theft, Cyber Security, Cybersecurity, Internet, MacOS, Malware, Python, social engineering, supply chain attack
Share This Article
Facebook Twitter Copy Link
Previous Article Volunteers in the Canary Islands guide African migrants through water trauma
Next Article Israeli strike on Gaza school 'kills 30'
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

AI’s power and water consumption is worrying the agriculture sector: ‘Don’t forget that it is also required for us to grow food’
Business
Congress Should Codify Trump Order Ending Hong Kong’s Special Trade Status, Advisory Panel Says
Politics
S.T.A.L.K.E.R. 2: Heart of Chornobyl PS5 Graphics Analysis – How Does It Compare Against Xbox Series X and PC?
Gaming News
Trump Takes Aim at State AI Laws in Draft Executive Order
Tech News
2 UK shares I’d prefer to own over Lloyds stock right now
Business
Mevolaxy files for registration with the SEC
Crypto
Underdog Fantasy Promo Code FOXSPORTS: Bet $5, Get $100 on Wednesday's NBA Slate
Sports

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

AI’s power and water consumption is worrying the agriculture sector: ‘Don’t forget that it is also required for us to grow food’

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
AI’s power and water consumption is worrying the agriculture sector: ‘Don’t forget that it is also required for us to grow food’
November 20, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?