Novel ELF64 Remote Access Tool Embedded in Malicious PyPI Uploads
Analyzing a Linux-targeted malware campaign on the Python Package Index.

Analyzing a Linux-targeted malware campaign on the Python Package Index.


Examining the cascading effect of software supply chain compromises and their mitigation strategies.

Discussing the internals of our client compute node in the Dragonfly framework.
Browse the archive by the kind of work Vipyr publishes, from campaign tracking to package malware reverse engineering.
Campaign tracking, ecosystem abuse patterns, and malicious package activity.
Dependency risk, resolver behavior, and application-layer package security issues.
Operational notes, internals, and reference material for Vipyr systems and workflows.
Reverse engineering, payload behavior, and package-level malware tradecraft.
Longer investigations, ecosystem observations, and malware analysis published from Vipyr’s package response work.

Discussing a persistent threat actor group utilizing automated malware pipelines to productionize malware uploads.

Exploiting third party dependancies to bypass PyArmor obfuscation.