ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

10 malicious Python Libraries discovered on PyPI Repository

Security researchers from Israeli cybersecurity firm Check Point have discovered ten malicious packages on the Python Package Index (PyPI), a public code repository of software for the Python programming language used by Python developers.

 

The malicious packages have been removed from PyPI for their ability to harvest critical data points such as passwords and API tokens. They could install info-stealers that enable attackers to steal the developer’s private data and personal credentials.

 

The offending packages include:

 

  • Ascii2text, which downloads a nefarious script that gathers passwords stored in web browsers such as Google Chrome, Microsoft Edge, Brave, Opera, and Yandex Browser. This malicious package mimicked the popular art package by name and description.
  • Pyg-utils, Pymocks, and PyProto2, which are designed to steal users’ AWS credentials
  • Test-async and Zlibsrc, which download and execute malicious code during installation
  • Free-net-VPN, Free-net-vpn2, and WINRPCexploit that steal user credentials and environment variables.
  • Browserdiv, which can collect credentials and other information saved in the web browser’s Local Storage folder.

 

Once the security researchers identified these malicious users and packages, they reportedly alerted PyPI via their official website. Following the disclosure, PyPI removed these packages, the advisory concluded.

 

Notably, several malicious open-source packages have previously been discovered on the PyPI repository. The JFrog Security research team found 11 new malware packages in November 2021 that had received over 40,000 downloads from PyPI. In July, the PyPI repository’s team began enforcing the two-factor authentication (2FA) policy for projects labeled as “critical” to decrease the number of malicious packages on the platform.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543