New malicious PyPI package beautifyText hides cross-platform backdoor, evades VirusTotal
cyb3rops · x · 2026-09-30
Nextron Research's THOR Thunderstorm-based scanning pipeline discovered a new malicious PyPI package, beautifyText, disguised as a harmless text-formatting utility for terminals, logs, and CLI output — with zero detections on VirusTotal.
- Installation and import appear routine, but beautifyText/init.py silently loads compat.py
- That module launches a detached process and connects to an obfuscated C2 server at bleodw[.]wisp[.]uno
- The backdoor registers the host, reports system/user info, polls for tasks, executes arbitrary shell commands, exfiltrates files, and writes attacker-supplied files
Anyone who installed the package should audit and clean their environments immediately.
More from Safety
- UK AISI test: autonomous AI cyberattack costs as little as $1.19 per attempt — OmarUFlorez · 2026-09-30
- Bill Gates: if a robot replaces a worker, why doesn't it pay into the pension fund? — _akpiper · 2026-09-30
- AI bots are aggressively mining library websites, straining open-access resources — _akpiper · 2026-09-30
- gmiller rebuts 'own assets and you'll be safe': AI smart enough to take your job can take your assets — ZeroStateReflex · 2026-09-30
- Nvidia launching security layer that quarantines rogue AI agents within milliseconds — TansuYegen · 2026-09-30
- OpenAI self-replicating prompt was misreported, Zvi clarifies it wasn't found in the wild — TheZvi · 2026-09-30