Malicious PyPI Packages Deliver SilentSync RAT
Essential information
- Published
- 19/09/2025 16:05
- Modified
- 19/09/2025 18:43
- Tags
- 2025-09-18 2025-09-19 browser data theft data exfiltration data theft pypi python python packages rat remote access silentsync supply chain attack supply-chain typosquatting
- Related entities
- 2 techniques (mitre), 1 malware, 3 others
Description
Two malicious Python packages, sisaws and secmeasure, were discovered in the Python Package Index (PyPI) repository. These packages, created by the same author, deliver a Remote Access Trojan (RAT) called SilentSync. The RAT is capable of remote command execution, file exfiltration, screen capturing, and web browser data theft. It specifically targets Windows systems and communicates with a command-and-control server using HTTP. The packages use typosquatting and mimic legitimate packages to deceive users. SilentSync achieves persistence through platform-specific techniques and can harvest browser data, execute shell commands, capture screenshots, and steal files. This discovery highlights the growing risk of supply chain attacks within public software repositories.