Security News > 2021 > June > Malicious PyPI packages hijack dev devices to mine cryptocurrency
This week, multiple malicious packages were caught in the PyPI repository for Python projects that turned developers' workstations into cryptomining machines.
All malicious packages were published by the same account and tricked developers into downloading them thousands of times by using misspelled names of legitimate Python projects.
Ax Sharma, a security researcher at devops automation company Sonatype, analyzed the "Maratlib" package in a blog post, noting that it was used as a dependency by the other malicious components.
"For each of these packages, the malicious code is contained in the setup.py file which is a build script that runs during a package's installation," the researcher writes.
In this case, the six malicious packages were caught by Sonatype after scanning the PyPI repo with its automated malware detection system, Release Integrity.
At detection time, the packages had accumulated almost 5,000 downloads since April, with "Maratlib" recording the highest download count, 2,371.