Malicious Python packages replace crypto addresses in developer clipboards
blog.phylum.io
blog.phylum.io
And it's why in any good hardware wallet, you need to explicitly confirm the address you're transferring to on the wallet's air gapped screen and make sure it wasn't swapped in the copy/paste.
I'm sure it would also be quite easy for this kind of attacker to generate thousands of addresses they control, and have their software pick one that looks 'closest' to the one being subverted to increase the likelihood that a lazy user just sanity checks a few characters at the beginning and end of the address before confirming.
Survival of the most paranoid.
This is probably a good lesson in general for intelligent malicious actors. If you have an exploit that works, it's important that you use it rarely enough and against the right marks that the loss doesn't enter the collective consciousness as a malicious attack, but simply as an individual or systemic failure.
And for those of us who strive to be constructive and defensive actors, it's an important lesson to remember that sometimes malicious actors disguise their actions as amoral bugs in the system. Regular random auditing of the seemingly mundane is an important tool to uncover these kinds of exploits.
Pieter Wuille has a very interesting talk on public addresses and some novel work he did to drastically improve address error detection. Worth a watch for some cool computer science. https://www.youtube.com/watch?v=NqiN9VFE4CU
Honestly, it's kind of surprising that these kinds of exploits don't happen all the time since base layer bitcoin transactions alone secure $14 trillion in annual transfer volume in recent years. That's a huge honey pot for malicious attackers that seems to mostly go under exploited.
I’m sure there would be an even more interesting variant where the address could be used to generate a prompt for DALL-E.
(With some --ignore-typo-suggestion just in case of automated edge-cases, of course :)
In this way a `phylum npm install <pkgName>` would perform the typosquat checks _and_ limit access to system resources. You can even alias this as `alias npm="phylum npm"` so that it's easier for the user.
The problem is that the information density of replacing hex with words is quite low, on the order of 14 bits per word, but much longer than the four letters needed to represent 16 bits in hex, which is itself a lot less dense than base64. You’d need 12 words to uniquely identify a sha-1 hash and most modern algorithms are less dense than that. But it would be harder to trick someone.
Maybe there’s some sort of 5:4 coding system that’s easier for humans to scan, still to be discovered out there?
I'm happy to be proven wrong by someone who finds something in the middle. Preferably without using emojis...
[0] https://blog.sonatype.com/sonatype-releases-new-nexus-firewa...
This campaign is ongoing. Our system just notified us of two more packages, which have been reported to PyPI. I expect this list to continue to grow throughout the day.
As a related aside, we are working on a package sandbox that prevents access to disk, network and env variables during package installation. It's not quite ready for primetime, but it is completely open source and we'd love some early feedback/contributions!
https://github.com/phylum-dev/birdcage
If anyone has any questions, I'd be more than happy to answer them!
This is currently offered as a SaaS solution, but we'll be providing an on-prem offering by EOY that should work well in an air-gapped environment.
The sandbox I mentioned above is rolled into our CLI by default, but that should operate well enough on its own without needing to call out to our API if you wanted!
Apps couldn’t get away with this sort of thing on iOS or Android. It’s inconvenient, but we need to raise the bar in the same way for security permissions and sandboxing on the desktop. (But obviously, with the user in control.)
Allows you to specify the allowed permissions in a toml file. Still a wip, but would love some feedback!
If every time I wanted to pay for a coffee I was risking losing all my savings, then I (and millions of others) would go back to cash
I am not sure where that leaves us for "digital native cash". Perhaps phones and secure enclaves will save us, perhaps we just have to pay the Visa tax.
Cryptocurrency aside, it definitely looks like these attacks are ramping up and we - the developers with access to critical infrastructure - are the primary targets. Today its crypto, tomorrow it's SSH keys.
It's both worrisome and tremendously annoying.
The keys to pretty much every online kingdom are only 2048 bits long and once the methods to exfiltrate crypto have been honed it's worth looking at ways to weaponise the others.
Oh it _absolutely_ is!
We're working extremely hard here and I think we're making great strides. More hard work to come, but I think it's absolutely worth the effort!