SilentSync delivery via malicious PyPI packages sisaws and secmeasure
Malware Activity
Summary
Hide ▲
Show ▼
Two malicious PyPI packages now expand the supply-chain risk for Python developers by delivering the SilentSync RAT to Windows systems. The packages, sisaws and secmeasure, were uploaded by CondeTGAPIS and later removed from the repository. One package impersonated the legitimate sisa library, while the other posed as a benign security utility. SilentSync can execute commands, steal files, capture screens, and harvest browser credentials and cookies.
Related Happenings
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
Campaign
H score56
First: 12.05.2026 14:29
Last: 12.05.2026 14:29
Sources 1
About this happening:
GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials
CampaignAbout this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...
Mini Shai-Hulud npm supply-chain malware wave
Malware Activity
H score68
First: 12.05.2026 14:07
Last: 12.05.2026 14:07
Sources 1
About this happening:
The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Mini Shai-Hulud npm supply-chain malware wave
Malware ActivityAbout this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...
Latest development: 09.06.2026 18:42
On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.
ZiChatBot PyPI supply-chain malware delivery
Malware Activity
H score30
First: 07.05.2026 12:20
Last: 07.05.2026 12:20
Sources 1
About this happening:
A PyPI supply-chain attack used three packages to quietly deliver ZiChatBot, creating a cross-platform malware risk for Windows and Linux installs. The packages we...
ZiChatBot PyPI supply-chain malware delivery
Malware ActivityAbout this happening: A PyPI supply-chain attack used three packages to quietly deliver ZiChatBot, creating a cross-platform malware risk for Windows and Linux installs. The packages we...
Lightning PyPI router_runtime.js credential-stealing payload
Malware Activity
H score29
First: 30.04.2026 19:31
Last: 30.04.2026 19:31
Sources 1
About this happening:
The Lightning PyPI package was pushed in malicious versions 2.6.2 and 2.6.3 on April 30, 2026, turning a normal install into credential theft for developer and C...
Lightning PyPI router_runtime.js credential-stealing payload
Malware ActivityAbout this happening: The Lightning PyPI package was pushed in malicious versions 2.6.2 and 2.6.3 on April 30, 2026, turning a normal install into credential theft for developer and C...
Latest development: 04.05.2026 20:15
Microsoft Threat Intelligence says Defender detected and prevented the malicious `lightning==2.6.3` routine in customer environments, notified the Lightning maintainer, and warned that users who ran `import lightning` may need to rotate exposed secrets, keys, and tokens.
Elementary-data package hit by network compromise
Incident
H score36
First: 27.04.2026 18:17
Last: 27.04.2026 18:17
Sources 1
About this happening:
The elementary-data project suffered a malicious release compromise that exposed users of PyPI and GitHub Container Registry to a backdoored package and image. An...
Elementary-data package hit by network compromise
IncidentAbout this happening: The elementary-data project suffered a malicious release compromise that exposed users of PyPI and GitHub Container Registry to a backdoored package and image. An...
Timeline
-
18.09.2025 14:38 2 articles · 10mo ago
Malicious PyPI packages deliver SilentSync RAT
Initial DisclosureResearchers disclosed two malicious PyPI packages, sisaws and secmeasure, uploaded by CondeTGAPIS and designed to deliver the SilentSync RAT to Windows systems. The sisaws package mimics the legitimate sisa library and uses gen_token() to decode a curl command that fetches a PasteBin-hosted Python script into helper.py for execution, while secmeasure masquerades as a string-cleaning and security utility but also drops SilentSync. SilentSync can execute shell commands, steal files, capture screenshots, and harvest browser data such as credentials, history, autofill data, and cookies from Chrome, Brave, Edge, and Firefox, and it also includes Linux and macOS persistence behaviors and a command server at 200.58.107[.]25 with /checkin, /comando, /respuesta, and /archivo endpoints.
Show sources
- SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers — thehackernews.com — 18.09.2025 14:38
- SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers — thehackernews.com — 18.09.2025 14:38