Exposed: Stealthy PyPI Packages Weaponize Gmail to Compromise Systems After 4 Years Undetected
Socket researchers discovered seven malicious PyPI packages impersonating "Coffin" that accumulated 55,000+ downloads over four years. The malware used Gmail SMTP servers for initial reconnaissance and WebSockets for persistent access, enabling attackers to execute commands, exfiltrate dat...
