216.73.217.22

PyPI Supply Chain Attack Uncovered: Colorama and Colorizr Name Confusion

· Published 02/06/2025 22:02 · Modified 02/06/2025 22:11

Export JSON

Essential information

Published
02/06/2025 22:02
Modified
02/06/2025 22:11
Tags
2025-06-02 colorama colorizr data exfiltration npm pypi remote access supply chain attack typosquatting
Related entities
2 observables, 7 techniques (mitre)

Description

A malicious package campaign targeting Python and users on Windows and Linux has been discovered. The attack uses typo-squatting and name-confusion tactics against the popular Python package and the similar JavaScript package. Multiple packages with risky payloads were uploaded to , using names similar to legitimate packages in both and . The unusual tactic of using an package name to attack users was observed. The payloads allow , control of desktops and servers, and exfiltration of sensitive data. Windows payloads attempt to bypass antivirus protection. The campaign's sophistication suggests targeted adversarial activity, although attribution remains unclear.

External references