Nov. 11, 2022, 12:51 a.m. | Pierluigi Paganini

Security Boulevard securityboulevard.com

Researchers warn of malicious packages on PyPI using steganography


Experts discovered a malicious package on the Python Package Index (PyPI) that uses steganographic to hide malware within image files.


CheckPoint researchers discovered a malicious package, named ‘apicolor,’ on the Python Package Index (PyPI) that uses steganographic to hide malware within image files.


The malicious package infects PyPI users through open-source projects on Github. 




The package was uploaded to PyPI on October 31, 2022, it had a vague header …

malicious malicious packages packages pypi researchers steganography

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Solution Architect

@ Civica | London, England, United Kingdom

Information Security Officer (80-100%)

@ SIX Group | Zurich, CH

Cloud Information Systems Security Engineer

@ Analytic Solutions Group | Chantilly, Virginia, United States

SRE Engineer & Security Software Administrator

@ Talan | Mexico City, Spain