
Russia-linked ‘Lumma’ crypto stealer now targets Python devs
Imagine being a developer who’s building the next-gen crypto app by using popular open source components to speed up coding. Instead, you end up including a package in your build that, does accomplish what you are trying to, but additionally steals cryptocurrency on any system that it’s installed on. That’s ‘crytic-compilers’ for you.
Sonatype’s automated malware detection systems identified a ‘crytic-compilers’ PyPI package named very closely after a fairly known legitimate Python library which is used by cryptocurrency developers to facilitate compilation of smart contracts, or digital agreements which are stored on the blockchain network.
*** This is a Security Bloggers Network syndicated blog from 2024 Sonatype Blog authored by Ax Sharma. Read the original post at: https://www.sonatype.com/blog/crytic-compilers-typosquats-known-crypto-library-drops-windows-trojan