Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialThe malicious libraries both attempt a similar attack, overwriting the legitimate clw cli command with malicious code that attempts to exfiltrate sensitive database files.
The developers responsible for the scam libraries appear to have joined in a discussion with other bitcoinlib developers and attempted to get the bitcoinlibdbfix library downloaded and run. However, the malicious content of that library was detected by the package contributors and the comments were deleted.
The second malicious package, bitcoinlib-dev, was uploaded to PyPI shortly after the first package was removed from the package manager, but it has now been removed and is not available for download.
While the threat remains on PyPI, ReversingLabs' detection of the malicious packages is evidence of the growing power of AI and ML in detecting emerging software supply chain attacks.
Both the bitcoinlibdbfix and bitcoinlib-dev packages were flagged in RL’s Spectra platform using ML algorithms that can detect novel malware by analyzing the behaviors that software components exhibit. It then flags those that resemble behaviors associated with previously discovered malware campaigns and software supply chain attacks.
By encapsulating threat hunting intelligence similar to discrete security policies such as these, Spectra is capable of spotting emerging threats in Python and other open-source packages — even absent social engineering campaigns such as the one carried out by the developers of the malicious bitcoinlib packages.
Automated detection like this is critical if software publishers and end-user organizations hope to shield themselves from the rising tide of software supply chain attacks targeting cryptocurrency.
Karlo Zanki, reverse engineer at ReversingLabs, said that using open-source packages in a development environment and software project "can pose a significant security risk.”
Karlo ZankiAutomated ML detections are the only way to implement real-time protection from emerging threats that bypass traditional signature-based detection mechanisms. The number of new packages that get published on a daily basis is posing a challenge for security organizations, and ML model-based detection is currently the best answer that the security industry can provide.




Aurastealer, ACRStealer, and RemusStealer, a new potential LumaStealer variant, show MaaS in action. Here's what you need to know.

SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.

One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.