Splunk Enterprise Security released analytics to detect malicious Python package installations that execute attacker code during installation or persist through Python startup mechanisms. The coverage flags abuse of setup.py, distutils/setuptools command classes, .pth files, sitecustomize.py, usercustomize.py, and PYTHONPATH; these techniques can execute arbitrary code during package installation or whenever a user later starts Python. The detections were informed by TeamPCP's compromise of the litellm package, which used .pth-based persistence, and VIPERTUNNEL's abuse of Python site hooks.
The endpoint analytics correlate Sysmon process-creation and file-creation events to identify .pth files created in site-packages or dist-packages, and correlate Sysmon Event IDs 1 and 13 to identify PYTHONPATH registry changes associated with pip and site-package activity. A malicious PYTHONPATH can redirect imports to attacker-controlled directories, analogous to PATH-search-order hijacking in which a malicious executable is resolved before the legitimate one. Security teams should enable the required Sysmon and CIM telemetry, investigate anomalous package-install activity and environment-variable changes, and tune for legitimate editable installs, namespace packages, developer workflows, and installer configuration changes.

See real exploitation activity before you spend the cycle.
19 events from the most recent confirmed update back to the earliest known activity.
Splunk Enterprise Security updated its anomaly detection for outbound network connections made by Python processes during package builds or installations. The analytic uses Sysmon process-creation and network-connection telemetry to identify potential malicious setup.py-driven beacons associated with software supply-chain compromise.
Splunk Enterprise Security updated its TTP analytic for PYTHONPATH registry modifications associated with Python package installation, using Sysmon process and registry telemetry.
Splunk Enterprise Security updated its anomaly detection for Python .pth file creation during package installation, correlating Sysmon process-creation and file-creation telemetry.
Splunk Enterprise Security updated its Malicious Python Package Installation analytic story, covering install-time code execution and persistence through .pth files, site hooks, and PYTHONPATH manipulation.
The VIPERTUNNEL backdoor was associated with abuse of Python sitecustomize.py or usercustomize.py hooks to establish persistence.
TeamPCP used Python .pth-based persistence during its supply-chain compromise of the litellm package.
Threat Group-3390 compromised the Able Desktop installer to gain access to victim environments.
During the SolarWinds compromise, SUNSPOT was used to insert SUNBURST into SolarWinds Orion builds, and APT29 gained initial network access to some victims through trojanized Orion updates.
Sandworm Team replaced a legitimate update for Ukrainian accounting software M.E.Doc with a malicious update to spread NotPetya.
Moonstone Sleet distributed a trojanized version of PuTTY to gain initial access to victims.
GoldenSpy was packaged with legitimate tax-preparation software for distribution to users.
GOLD SOUTHFIELD distributed ransomware by backdooring software installers after strategically compromising the website hosting Italian WinRAR.
FIN7 gained initial access to victim environments by compromising a victim's software supply chain.
Dragonfly placed trojanized installers for control-system software in legitimate vendor application stores.
Daggerfly was associated with supply-chain compromises that used malicious updates to compromise victims.
Cobalt Group compromised legitimate web-browser updates to deliver a backdoor.
CCBkdr was added to a legitimate signed version 5.33 of CCleaner and distributed through CCleaner's distribution site.
APT41 accessed production environments and injected malicious code into legitimate signed files that were then widely distributed to end users.
During the 3CX supply-chain attack, AppleJeus first compromised an end-of-life trading application executed in the 3CX environment, then modified the Windows and macOS build environments used to distribute 3CX software.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.