216.73.217.22

Malicious PyPI Packages Deliver SilentSync RAT

· Published 19/09/2025 16:05 · Modified 19/09/2025 18:43

Export JSON

Essential information

Published
19/09/2025 16:05
Modified
19/09/2025 18:43
Tags
2025-09-18 2025-09-19 browser data theft data exfiltration data theft pypi python python packages rat remote access silentsync supply chain attack supply-chain typosquatting
Related entities
2 techniques (mitre), 1 malware, 3 others

Description

Two malicious , sisaws and secmeasure, were discovered in the Package Index () repository. These packages, created by the same author, deliver a Trojan () called . The is capable of remote command execution, file exfiltration, screen capturing, and web . It specifically targets Windows systems and communicates with a command-and-control server using HTTP. The packages use and mimic legitimate packages to deceive users. achieves persistence through platform-specific techniques and can harvest browser data, execute shell commands, capture screenshots, and steal files. This discovery highlights the growing risk of supply chain attacks within public software repositories.

External references