216.73.216.226

Backdoor implant discovered on PyPI posing as debugging utility

· Published 15/05/2025 20:12 · Modified 21/05/2025 20:35

Export JSON

Essential information

Published
15/05/2025 20:12
Modified
21/05/2025 20:35
Tags
2025-05-15 backdoor dbgpkg discordpydebug function wrapping global socket toolkit hacktivist pypi requestsdev russia supply chain attack ukraine
Related entities
1 intrusion sets (apt), 12 techniques (mitre), 2 malware, 2 others

Description

A sophisticated malicious package named '' was detected on , masquerading as a Python debugging utility. The package implants a on systems, enabling execution of malicious code and data exfiltration. It uses techniques to evade detection and is believed to be part of a larger campaign possibly linked to a group known as Phoenix Hyena. The campaign also includes other packages like '' and ''. The attackers' motivation appears to be geopolitical, potentially related to the - conflict. The use of specific backdooring techniques and tools like indicates a high level of sophistication and an intent to establish long-term presence on compromised systems.

External references