‘Netfetcher’ package drops illicit ‘node’ binary on Windows
2024-8-23 00:15:0 Author: securityboulevard.com(查看原文) 阅读量:2 收藏

'Netfetcher' package drops illicit 'node' binary on Windows

Recently identified PyPI packages called “netfetcher” and “pyfetcher” impersonate open source libraries and target Windows users with malicious executables that have a zero detection rate among leading antivirus engines. Furthermore, some of these executables are called “node.exe” and even bear the NodeJS icon and metadata, making them evasive and easily mistaken for legitimate libraries.

*** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/pyfetcher-netfetch-drop-netflix-checker-on-windows


文章来源: https://securityboulevard.com/2024/08/netfetcher-package-drops-illicit-node-binary-on-windows/
如有侵权请联系:admin#unsafe.sh