The PyPI (Python Package Index) has identified several packages that include code for hidden cryptocurrency mining. Issues were found in the packages maratlib, maratlib1, matplatlib-plus, mllearnlib, mplatlib, and learninglib, whose names are similar to popular libraries (matplotlib), with the expectation that users would make typographical errors and not notice the differences (typosquatting). The packages were uploaded in April under the account nedog123 and were downloaded approximately 5,000 times over two months.
Malicious code was embedded in the maratlib library, which was used in the other packages as a dependency. The malicious code was concealed using a custom obfuscation mechanism, undetectable by standard utilities, and executed during the running of the setup.py build script performed during package installation. The setup.py would download a bash script aza.sh from GitHub, which in turn would download and run cryptocurrency mining applications Ubqminer or T-Rex.
Source: opennet.ru
