Tuesday, 14 Apr 2026
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Politics
  • Technology
  • Travel
  • World
  • Finance
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

Gmail servers hijacked by malicious PyPI packages to spread havoc – here’s how to stay safe

Nexpressdaily
Last updated: May 5, 2025 1:14 pm
Nexpressdaily
Share
SHARE


  • Socket found seven malicious packages on PyPI
  • The packages were abusing Gmail and WebSocket
  • They were removed from the platform

Several malicious PyPI packages were recently observed abusing Gmail to exfiltrate stolen sensitive data and communicate with their operators.

Cybersecurity researchers Socket, who found the packages, reported them to the Python repository and thus helped get them removed from the platform – however the damage has already been done.

According to Socket, there were seven malicious PyPI packages, some of which were sitting on the platform for more than four years. Cumulatively, they had more than 55,000 downloads. Most are an imitation of the legitimate Coffin package, with names like Coffin-Codes-Pro, Coffin-Codes, NET2, Coffin-Codes-NET, Coffin-Codes-2022, Coffin2022, and Coffin-Grave. One was called cfc-bsb.


You may like

Compromised hosting accounts

The researchers explained that once the package is installed on the victim device, it connects to Gmail using hardcoded credentials, and contacts the C2 server.

It then creates a tunnel using WebSockets, and since Gmail’s email server is being used for communication, the communication bypasses most firewalls and other security measures.

As a result, the attackers are able to send commands, steal files, run code, and even access systems remotely.

However, it seems that the crooks were mostly interested in crypto theft, since one of the email addresses the malware was reaching out to had the words “blockchain” and “bitcoin” it it:

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“Coffin-Codes-Pro establishes a connection to Gmail’s SMTP server using hardcoded credentials, namely sphacoffin@gmail[.]comand a password,” the report says.

“It then sends a message to a second email address, blockchain[.]bitcoins2020@gmail[.]com politely and demurely signaling that the implant is working.”

Socket has warned all Python users running any of the packages in their environment to remove them immediately and rotate keys and credentials as needed.

The researchers also urged everyone to watch for unusual outbound connections, “especially SMTP traffic”, and warned them not to trust a package just because it was a few years old.

“To protect your codebase, always verify package authenticity by checking download counts, publisher history, and GitHub repository links,” they added.

“Regular dependency audits help catch unexpected or malicious packages early. Keep strict access controls on private keys, carefully limiting who can view or import them in development. Use isolated, dedicated environments when testing third-party scripts to contain potentially harmful code.”

Via BleepingComputer

You might also like

Share This Article
Email Copy Link Print
Previous Article Canada election: Ontario riding flips to Liberals after validation process
Next Article Trump proposes 100% tariff on foreign-made movies as he declares Hollywood critical to U.S. national security

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

Why Trump Is Trying to Send Deportees to South Sudan

On May 20th, a flight with eight deportees left Texas headed to South Sudan, a…

By Nexpressdaily

One of the Most Celebrated Astronomical Events of 2025 Is Peaking This Week

Make sure to look up at the night sky this week because Mother Nature is…

By Nexpressdaily

Welcome to Slovenia: a land of medieval castles, sprawling forests and a Passion Play | Slovenia Your Way

Boutique destinations offering authentic, off-the-beaten-track experiences are becoming the way to travel, as holidaymakers increasingly…

By Nexpressdaily

You Might Also Like

Technology

Today’s NYT Mini Crossword Answers for July 27

By Nexpressdaily
Technology

Meta’s beef with the press flares at its antitrust trial

By Nexpressdaily
Technology

Save on MacBooks, Windows 11 machines, Chromebooks and others before the sale ends

By Nexpressdaily
Technology

The frenzied, gamified chase for Labubus

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?