JFrog Security Research discovered a sophisticated malicious PyPI package called 'chimera-sandbox-extensions' that targets Chimera Sandbox users through a multi-stage attack. The malware uses a domain generation algorithm to connect to command-and-control servers, steals sensitive corporate data including AWS tokens, CI/CD

7m read timeFrom jfrog.com
Post cover image
Table of contents
Payload AnalysisConclusion

Sort: