SentinelOne impersonated via PyPI packages
High severity
GitHub Reviewed
Published
Dec 27, 2022
to the GitHub Advisory Database
•
Updated Jan 12, 2023
Description
Published to the GitHub Advisory Database
Dec 27, 2022
Reviewed
Dec 27, 2022
Last updated
Jan 12, 2023
In December 2022, threat actors impersonated SentinelOne by uploading fake software development kits (SDKs) onto PyPI. The SDKs contain fully functional SentinelOne clients, but the packages also contained malicious backdoors that are only executed when called on programmatically, as opposed to during installation. The packages have since been taken down from PyPI.
References