September 25, 2023

Attackers are using W4SP stealer, for creating fake Python packages and use rudimentary obfuscation techniques in an attempt to infect developers.

W4SP, a trojan that is designed to steal crypto information, exfiltrate sensitive data, and collect credentials from developers’ systems.

A threat actor has created 29 clones of popular software packages on PyPI, giving them benign sounding names or purposefully giving them names similar to legitimate packages, a practice known as typosquatting.


Open source software components distributed through repository services, such as PyPI and the NPM are a popular vector of attacks, as the number of dependencies imported into software has grown dramatically.

These packages are a more sophisticated attempt to deliver the W4SP Stealer onto Python developer’s machines, and the ongoing attack constantly changing tactics and its difficult to predict the outcome.

The eventual goal of the attack is to install the information-stealing Trojan W4SP Stealer, which enumerates the victim’s system, steals browser stored passwords, targets cryptocurrency wallets.


Researchers made some progress in identifying the attacker and has sent reports to the companies whose infrastructure is being used. Till now 5700 downloads of the malicious package has been made.

This research was documented by researchers from Phylum.

Leave a Reply

%d bloggers like this: