Sept. 19, 2023, 7:35 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


Key Points



  • A malicious Python package, “Culturestreak”, hijacks system resources for unauthorized cryptocurrency mining.

  • The malicious package utilizes obfuscated code and random filenames to evade detection.

  • The code runs in an infinite loop, making it a relentless threat that continually exploits system resources.

  • The malicious code originates from an active GitLab repository, underscoring the ongoing risk to users.


Recently, our team came across a Python package named “culturestreak”. A closer look reveals a darker purpose: unauthorized cryptocurrency mining. Let’s break …

attacker code crypto cryptocurrency cryptocurrency mining crypto mining detection evade exploits gitlab key key points loop making malicious mining obfuscated package points python python package random resources system threat

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Cloud Security Engineer

@ Gainwell Technologies | Any city, OR, US, 99999

Federal Workday Security Lead

@ Accenture Federal Services | Arlington, VA

Workplace Consultant

@ Solvinity | Den Bosch, Noord-Brabant, Nederland

SrMgr-Global Information Security - Security Risk Management

@ Marriott International | Bethesda, MD, United States

Sr. Security Engineer - Data Loss Prevention

@ Verisk | Jersey City, NJ, United States