{"id":1163059,"date":"2024-02-23T16:36:26","date_gmt":"2024-02-23T18:36:26","guid":{"rendered":"https:\/\/teknomers.com\/fr\/package-pypi-dormant-compromis-pour-propager-le-logiciel-malveillant-nova-sentinel\/"},"modified":"2024-02-23T16:36:30","modified_gmt":"2024-02-23T18:36:30","slug":"package-pypi-dormant-compromis-pour-propager-le-logiciel-malveillant-nova-sentinel","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/package-pypi-dormant-compromis-pour-propager-le-logiciel-malveillant-nova-sentinel\/","title":{"rendered":"Package PyPI dormant compromis pour propager le logiciel malveillant Nova Sentinel"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">23 f\u00e9vrier 2024<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">R\u00e9daction<\/span><\/span><span class=\"p-tags\">Attaque de la cha\u00eene d&#8217;approvisionnement\/logiciel malveillant<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/Package-PyPI-dormant-compromis-pour-propager-le-logiciel-malveillant-Nova.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><\/a><\/div>\n<p>Un package dormant disponible sur le r\u00e9f\u00e9rentiel Python Package Index (PyPI) a \u00e9t\u00e9 mis \u00e0 jour presque apr\u00e8s deux ans pour propager un malware voleur d&#8217;informations appel\u00e9 Nova Sentinel.<\/p>\n<p>Le paquet, nomm\u00e9 <strong>Django-log-tracker<\/strong>a \u00e9t\u00e9 publi\u00e9 pour la premi\u00e8re fois sur PyPI en avril 2022, selon la soci\u00e9t\u00e9 de s\u00e9curit\u00e9 de la cha\u00eene d&#8217;approvisionnement logicielle Phylum, qui <a rel=\"nofollow noopener\" href=\"https:\/\/blog.phylum.io\/dormant-pypi-package-updated-to-deploy-novasentinel-stealer\/\" target=\"_blank\">d\u00e9tect\u00e9<\/a> une mise \u00e0 jour anormale de la biblioth\u00e8que le 21 f\u00e9vrier 2024.<\/p>\n<p>Tandis que le <a rel=\"nofollow noopener\" href=\"https:\/\/github.com\/Ragib01\/django_log_tracker\" target=\"_blank\">d\u00e9p\u00f4t GitHub li\u00e9<\/a> n&#8217;a pas \u00e9t\u00e9 mis \u00e0 jour depuis le 10 avril 2022, l&#8217;introduction d&#8217;une mise \u00e0 jour malveillante sugg\u00e8re une probable compromission du compte PyPI appartenant au d\u00e9veloppeur.<\/p>\n<p>Django-log-tracker a \u00e9t\u00e9 <a rel=\"nofollow noopener\" href=\"https:\/\/www.pepy.tech\/projects\/django-log-tracker\" target=\"_blank\">t\u00e9l\u00e9charg\u00e9 3 866 fois<\/a> \u00e0 ce jour, avec la version malveillante (1.0.4) t\u00e9l\u00e9charg\u00e9e 107 fois \u00e0 la date de sa publication.  Le package n&#8217;est plus disponible au t\u00e9l\u00e9chargement depuis PyPI.<\/p>\n<div class=\"check_two clear bobbob\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thehackernews.uk\/boundaries728\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1708021586_957_Ivanti-Pulse-Secure-detecte-a-laide-dune-version-Linux-vieille.jpg\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>&#8220;Dans la mise \u00e0 jour malveillante, l&#8217;attaquant a supprim\u00e9 le package de la majeure partie de son contenu d&#8217;origine, ne laissant derri\u00e8re lui qu&#8217;un fichier __init__.py et example.py&#8221;, a d\u00e9clar\u00e9 la soci\u00e9t\u00e9.<\/p>\n<p>Les changements, simples et explicites, impliquent de r\u00e9cup\u00e9rer un ex\u00e9cutable nomm\u00e9 &#8220;Updater_1.4.4_x64.exe&#8221; depuis un serveur distant (&#8220;45.88.180[.]54&#8221;), suivi de son lancement \u00e0 l&#8217;aide de Python <a rel=\"nofollow noopener\" href=\"https:\/\/docs.python.org\/3\/library\/os.html#os.startfile\" target=\"_blank\">Fonction os.startfile()<\/a>.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1708713386_879_Package-PyPI-dormant-compromis-pour-propager-le-logiciel-malveillant-Nova.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><img decoding=\"async\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1708713386_879_Package-PyPI-dormant-compromis-pour-propager-le-logiciel-malveillant-Nova.jpg\" alt=\"\" border=\"0\" data-original-height=\"527\" data-original-width=\"728\"\/><\/a><\/div>\n<p>Le binaire, quant \u00e0 lui, est int\u00e9gr\u00e9 \u00e0 Nova Sentinel, un malware voleur qui a \u00e9t\u00e9 document\u00e9 pour la premi\u00e8re fois par Sekoia en novembre 2023 comme \u00e9tant distribu\u00e9 sous la forme de fausses applications Electron sur de faux sites proposant des t\u00e9l\u00e9chargements de jeux vid\u00e9o.<\/p>\n<p>&#8220;Ce qui est int\u00e9ressant dans ce cas particulier [&#8230;] est que le vecteur d&#8217;attaque semblait \u00eatre une tentative d&#8217;attaque de la cha\u00eene d&#8217;approvisionnement via un compte PyPI compromis&#8221;, a d\u00e9clar\u00e9 Phylum.<\/p>\n<p>&#8220;S&#8217;il s&#8217;agissait d&#8217;un package tr\u00e8s populaire, tout projet avec ce package r\u00e9pertori\u00e9 comme d\u00e9pendance sans version sp\u00e9cifi\u00e9e ou version flexible sp\u00e9cifi\u00e9e dans son fichier de d\u00e9pendance aurait extrait la derni\u00e8re version malveillante de ce package.&#8221;<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2024\/02\/dormant-pypi-package-compromised-to.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80223 f\u00e9vrier 2024\ue804R\u00e9dactionAttaque de la cha\u00eene d&#8217;approvisionnement\/logiciel malveillant Un package dormant disponible sur le r\u00e9f\u00e9rentiel Python Package Index (PyPI) a \u00e9t\u00e9 mis \u00e0 jour presque apr\u00e8s deux ans pour propager un malware voleur d&#8217;informations appel\u00e9 Nova Sentinel. Le paquet, nomm\u00e9 Django-log-trackera \u00e9t\u00e9 publi\u00e9 pour la premi\u00e8re fois sur PyPI en avril 2022, selon la soci\u00e9t\u00e9 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1163060,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[200292,4168,20350,4165,4161,200267,62243,4159,4171,6816,200271,7733,200268,200269,200270,30576,7878,185,29861,69497,128318,4172,4169,231498,4166,4164],"class_list":["post-1163059","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actualites-sur-la-cybersecurite","tag-comment-pirater","tag-compromis","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-cyberactualites","tag-dormant","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-logiciel","tag-logiciel-malveillant-rancongiciel","tag-malveillant","tag-mises-a-jour-sur-la-cybersecurite","tag-nouvelles-des-pirates","tag-nouvelles-sur-le-piratage","tag-nova","tag-package","tag-pour","tag-propager","tag-pypi","tag-securite-des-informations","tag-securite-informatique","tag-securite-internet","tag-sentinel","tag-violation-de-donnees","tag-vulnerabilite-logicielle"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1163059","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=1163059"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1163059\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/1163060"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=1163059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=1163059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=1163059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}