• n0xew
    link
    English
    8
    edit-2
    1 day ago

    I agree the article isn’t super clear. Reading it twice, it seems that the user credentials are exfiltrated to the C2 server (only the screenshot implies it), which definitely would be malicious.

    Also a possible interpretation could be that the package advertised “just” some automations (e.g. export playlists to m3u?) and getting music metadata, whereas it was actually downloading musics locally unbeknownst to the user. Then exfiltrating the music back to the C2 server, effectively using the package’s users to mass pirate musics without exposing the pirates directly. That would indeed be malicious, especially if the package did not advertise any content downloading.

    But for the last paragraph I’m extrapolating on the few info this article gives without making much sense…

    EDIT: from the original article here https://socket.dev/blog/malicious-pypi-package-exploits-deezer-api-for-coordinated-music-piracy it does not seem that the musics are downloaded on the user systems then extracted to the C2 server, but rather all that’s necessary to build the download urls, including tokens tied to the victims’ account.

    • @kiagam
      link
      English
      61 day ago

      I see, makes sense, so the problem is that the user tokens are collected without knowledge and could be used for pirating