“Previously, threat actors used this tactic to siphon private keys to Solana,” notes Socket’s report shared with Cyber Security News. All seven packages have been removed from PyPI, but the technique represents an evolving threat that security teams should monitor closely as it aligns with the MITRE ATT&CK technique T1102.002 (Web Service: Bidirectional Communication). Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. The oldest package, cfc-bsb, released in March 2021, lacks email exfiltration capabilities but still implements suspicious WebSocket-based HTTP tunneling similar to Ngrok.
This Cyber News was published on cybersecuritynews.com. Publication date: Fri, 02 May 2025 08:40:12 +0000