Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



 109080

[Warning] Beware of the python source codes being posted here

by Nero - 05 August, 2023 - 05:32 AM
This post is by a banned member (Nero) - Unhide
Nero  
Reverser
868
Posts
152
Threads
5 Years of service
#1
(This post was last modified: 16 August, 2023 - 10:09 PM by Nero. Edited 4 times in total.)
 
Hello fellow members of c.io,

I'm reaching out today to raise
an important flag regarding the Python "open source" code snippets that you might come across on this forum. It has come to my attention that a concerning number of individuals, both forum members and potentially even some staff, seem to be overlooking potential security risks. (TL;DR available at the end of the the thread)


Allow me to show a specific example:
 
Show ContentSpoiler:

  At first glance, this code may seem innocent. There's no blatant indication of any attempt to access a Discord webhook, Telegram, or any external server that might suggest your data is being sent to a attacker. However, what many of you, may have missed upon initial inspection is the libraries being installed and executed:

Show ContentSpoiler:

  The hidden threat lies within the library named "pypiele." 

The tricky part happens behind the scenes:
pip install pypiele
(assuming the malicious library is disguised as "pypiele"), it downloads the malicious code onto your computer.

This code is saved in a location on your system,   
"AppData\Local\Programs\Python\PythonVersion\lib\nameofmalware"


Now, when you run the innocent-looking main.py script that you found online, it starts importing libraries, including the malicious "pypiele."
This means the harmful code gets executed alongside the legitimate code. The attacker's script could perform actions that compromise your privacy and security, like stealing your private information, logging your keystrokes, or taking unauthorized control of your system.

Here's the tricky part: The bad library can be different in is name. It might be called "pypypal" or something else each time. This makes it hard to spot.
It's important that we remain vigilant, especially in the realm of open source threads.

Don't let the apparent simplicity of a code snippet blind you to the potential risks it may conceal. By exercising caution and inspecting both the code and the libraries it employs, we can collectively work to ensure a safer and more secure coding environment.
Stay informed, stay safe.



How do i stay safe from this?
simple!

just go to

pypi.org

And look up the libraries name that you find within a open source python program and make sure they are legit.

-----------------------------------------------------------------------------

TL;DR :
When you run the innocent-looking main.py script that you found online, it starts importing libraries, including the malicious "pypiele" in our exemple. Don't let the apparent simplicity of a code snippet blind you, always look up the libraries name that you find within a open source python program and make sure they are legit using pypi.org
[Image: dnLkwa2.gif]
My Only Discord Account is shidot0ku discord ID : (933454757874528297) 
I do not have telegram.
This post is by a banned member (Nero) - Unhide
Nero  
Reverser
868
Posts
152
Threads
5 Years of service
#2
(05 August, 2023 - 05:37 AM)Ddarknotevil Wrote: Show More
(05 August, 2023 - 05:32 AM)Rune Wrote: Show More
Hello fellow members of c.io,
I'm reaching out today to raise an important flag regarding the Python "open source" code snippets that you might come across on this forum. It has come to my attention that a concerning number of individuals, both forum members and potentially even some staff, seem to be overlooking potential security risks. Despite my earlier report about a particular thread that is still active, it continues to spread malware that poses a threat to unsuspecting users.
Allow me to show a specific example:

Show ContentSpoiler:
At first glance, this code may seem innocent. There's no blatant indication of any attempt to access a Discord webhook, Telegram, or any external server that might suggest your data is being sent to a attacker. However, what many of you, may have missed upon initial inspection is the libraries being installed and executed:
Show ContentSpoiler:


the hidden threat lies within the library named "pypiele." If you were to execute this code without a second thought, the "pypiele" malware would discreetly operate in the background. Its purpose? To steal your information from your system, including browser logins, Discord tokens, and cookies.
Now The library module can be different each time. It can be named "he8hew98h3" or "pypyaal" or "example95" Since Is the Attacker's choice of name to upload. 
It's important that we remain vigilant, especially in the realm of open source threads. Don't let the apparent simplicity of a code snippet blind you to the potential risks it may conceal. By exercising caution and inspecting both the code and the libraries it employs, we can collectively work to ensure a safer and more secure coding environment.
Stay informed, stay safe.

This malware code was obtained from the user @Ehohjsuise < (this user is posting malware and staff still hasnt banned him just like other hundreds of users)

Thats Huge Thank you for the heads up , Now I know why my new paypal Account got hacked lol [Image: wack.png]

Even though we act like retards in SB, is important that we look out for each other in terms of security and safety.
[Image: dnLkwa2.gif]
My Only Discord Account is shidot0ku discord ID : (933454757874528297) 
I do not have telegram.
This post is by a banned member (ToFamSuper) - Unhide
This post is by a banned member (PureEvil) - Unhide
PureEvil  
Supreme
3.627
Posts
1.911
Threads
3 Years of service
#4
(05 August, 2023 - 07:17 AM)ToFamSuper Wrote: Show More
@Rune how do you actually decompile Python .exe back to the source code
is there any video or tutorial.

He didn't decompile it, he is just analyzing a source code from the source code section.
[Image: IDPGJHz.gif]
[Image: PlbfEaV.gif]
This post is by a banned member (Nero) - Unhide
Nero  
Reverser
868
Posts
152
Threads
5 Years of service
Bumped #5
This is a bump
This post is by a banned member (Rusty) - Unhide
Rusty  
Contributor
1.071
Posts
705
Threads
5 Years of service
#6
@Rune Congratulations for this, good find! Hope this thread will get pinned or new measures will be taken to fight against this ma'am
This post is by a banned member (Timi999) - Unhide
Timi999  
Contributor
492
Posts
71
Threads
3 Years of service
#7
this fr deserves to be pinned on here
This post is by a banned member (MUIBIEN) - Unhide
MUIBIEN  
Supreme
2.330
Posts
159
Threads
1 Year of service
#8
Thank you for this thread great work
Hope this helps people be more cautious

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 5 Guest(s)