By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials
Tech News

Malicious PyPI Package Targets macOS to Steal Google Cloud Credentials

By Viral Trending Content 3 Min Read
Share
SHARE

Jul 27, 2024NewsroomCybersecurity / Cloud Security

Malicious PyPI Package

Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that targets Apple macOS systems with the goal of stealing users’ Google Cloud credentials from a narrow pool of victims.

The package, named “lr-utils-lib,” attracted a total of 59 downloads before it was taken down. It was uploaded to the registry in early June 2024.

“The malware uses a list of predefined hashes to target specific macOS machines and attempts to harvest Google Cloud authentication data,” Checkmarx researcher Yehuda Gelb said in a Friday report. “The harvested credentials are sent to a remote server.”

Cybersecurity

An important aspect of the package is that it first checks if it has been installed on a macOS system, and only then proceeds to compare the system’s Universally Unique Identifier (UUID) against a hard-coded list of 64 hashes.

If the compromised machine is among those specified in the predefined set, it attempts to access two files, namely application_default_credentials.json and credentials.db, located in the ~/.config/gcloud directory, which contain Google Cloud authentication data.

Malicious PyPI Package

The captured information is then transmitted over HTTP to a remote server “europe-west2-workload-422915[.]cloudfunctions[.]net.”

Checkmarx said it also found a fake profile on LinkedIn with the name “Lucid Zenith” that matched the package’s owner and falsely claimed to be the CEO of Apex Companies, suggesting a possible social engineering element to the attack.

Exactly who is behind the campaign is currently not known. However, it comes more than two months after cybersecurity firm Phylum disclosed details of another supply chain attack involving a Python package called “requests-darwin-lite” that was also found to unleash its malicious actions after checking the UUID of the macOS host.

These campaigns are a sign that threat actors have prior knowledge of the macOS systems they want to infiltrate and are going to great lengths to ensure that the malicious packages are distributed only to those particular machines.

It also speaks to the tactics malicious actors employ to distribute lookalike packages, aiming to deceive developers into incorporating them into their applications.

“While it is not clear whether this attack targeted individuals or enterprises, these kinds of attacks can significantly impact enterprises,” Gelb said. “While the initial compromise usually occurs on an individual developer’s machine, the implications for enterprises can be substantial.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

The Ultimate Dolby Atmos Experience Might Be In Your Car

Samsung Tri-fold Foldable Named and Dated

AI’s Next Evolution: From Advisor to Architect – New TCS/MIT SMR Study Reveals Game-Changing Shift

9 Best Coolers WIRED Tested for Every Budget, Any Situation

Astronomers observe the earliest moments of a new solar system

TAGGED: Cloud security, Credential Theft, Cyber Security, Cybersecurity, Internet, MacOS, Malware, Python, social engineering, supply chain attack
Share This Article
Facebook Twitter Copy Link
Previous Article Volunteers in the Canary Islands guide African migrants through water trauma
Next Article Israeli strike on Gaza school 'kills 30'
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Dow futures turn higher as investors brace for a big week of earnings, housing market data and Jerome Powell
Business
UK working to sell $7B in seized Bitcoin to boost budget: Report
Crypto
Car crashes into a barn's roof in Germany, seriously injuring 2
World News
Crypto Exchange CoinDCX Falls Victim To $44 Million Hack – Details
Crypto
The Ultimate Dolby Atmos Experience Might Be In Your Car
Tech News
Littler fuelled for World Matchplay by 'hours and hours' of practice
Sports
Assassin’s Creed Shadows’ Development Budget Exceeded €100 Million
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Dow futures turn higher as investors brace for a big week of earnings, housing market data and Jerome Powell

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Dow futures turn higher as investors brace for a big week of earnings, housing market data and Jerome Powell
July 21, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?