See It All. Understand It All.
Published loading...Updated

Gmail servers hijacked by malicious PyPI packages to spread havoc - here's how to stay safe

  • Cybersecurity researchers Socket discovered seven malicious PyPI packages abusing Gmail servers to steal data and relay commands in 2025.
  • These packages, some active for over four years with more than 55,000 downloads, mainly mimic the legitimate Coffin package to evade suspicion.
  • Once installed, the malware uses hardcoded Gmail credentials to create communication tunnels via WebSockets, bypassing firewalls and enabling remote control.
  • One command-and-control email address included 'blockchain' and 'bitcoin', indicating attackers focused primarily on crypto theft, while Socket urged users to verify package authenticity.
  • Socket advised immediate removal of these packages, rotating credentials, limiting key access, and using isolated environments to mitigate ongoing security risks.
Insights by Ground AI
Does this summary seem wrong?

13 Articles

All
Left
8
Center
1
Right
The Peterborough ExaminerThe Peterborough Examiner
+8 Reposted by 8 other sources
Lean Left

Billions of Gmail users at risk with new phishing scam — here’s how to spot it

First highlighted on X by Nick Johnson, founder and chief developer of Ethereum Name Services (ENS), the phishing attack targets Gmail users with a convincing phishing site that uses a google.com subdomain and a message that seems to come from a legitimate no-reply@google.com address.

·Peterborough, Canada
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 89% of the sources lean Left
89% Left
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

insauga broke the news in on Sunday, May 4, 2025.
Sources are mostly out of (0)

Similar News Topics

You have read out of your 5 free daily articles.

Join us as a member to unlock exclusive access to diverse content.