Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Threat Actors Exploit DeepSeek’s Popularity to Distribute Infostealers on PyPI 
News & Analysis Artificial Intelligence Attacks

Threat Actors Exploit DeepSeek’s Popularity to Distribute Infostealers on PyPI 

Kirsten DoyleBy Kirsten DoyleFebruary 4, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Malicious actors have exploited the rising popularity of DeepSeek AI to distribute two malicious infostealer packages through the Python Package Index (PyPI), impersonating legitimate developer tools for the AI platform.  

Researchers at Positive Technologies discovered and reported the campaign, which targeted developers, machine learning engineers, and AI enthusiasts integrating DeepSeek AI into their systems. 

A Prime Target 

The malicious campaign was detected and mitigated by the Supply Chain Security team at the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC). PyPI serves as the default package repository for popular package managers such as pip, pipenv, and poetry, making it a prime target for supply chain attacks. 

On 29 January 2025, an account named bvk—created in June 2023 with no prior activity—uploaded two fraudulent packages: deepseeek and deepseekai. Both were designed to exfiltrate sensitive user and system data, including API keys, database credentials, and infrastructure access tokens. 

How it Worked 

Once executed, the malicious payloads in the packages collected and transmitted user and system data. The payload activated when users ran the respective package commands in the command-line interface. The malefactors specifically targeted environment variables, which often store critical application credentials and access tokens. 

The stolen data was sent to a command-and-control (C2) server hosted on Pipedream, a developer integration platform. According to the researchers, the script contained comments that bore telltale signs of AI-generated assistance, meaning an AI assistant was likely used to develop the malware. 

Impact and Response 

Despite the swift response by security researchers, the malicious packages were downloaded multiple times before removal. According to Positive Technologies: 

  • The packages were downloaded 36 times using the pip package manager and the Bandersnatch mirroring tool. 
  • One hundred eighty-six downloads occurred via browser requests, the requests library, and other tools. 

PyPI administrators were notified promptly, and the compromised packages were deleted. However, the incident is one more example of the growing threat of supply chain attacks within the open-source ecosystem. 

Supply Chain Risk 

 Jason Soroko, a senior fellow at Sectigo, says the researchers’ report unpacks a threat in which bad actors injected info stealer malware into the PyPI repository by disguising it as DeepSeek.  

“The findings confirm that attackers exploit trusted naming conventions and the open-source ecosystem’s reliance on authentic package sources. Although the report was published from a Russian domain, which may limit accessibility, the technical evidence underscores a growing risk in software supply chains.” 

Soroko said businesses must enforce strict package verification and monitor repository activity to mitigate potential breaches. 

 Trust Nothing 

Mike McGuire, Senior Security Solutions Manager at Black Duck, says: “In the early days of open source software, we were taught to treat the packages we used with inherent trust. We’re now in the era of having to treat every package that we download or use with a reasonable level of scrutiny.” 

McGuire says although this attack involved the name DeepSeek, it’s important to note that this had nothing to do with the company, or with AI at all. Instead, it has everything to do with criminals seizing an opportunity in the popularity of AI tools in the development community. 

Missing Red Flags 

  “In their eagerness to leverage DeepSeek in their tasks, many developers missed the “red flag” that they were downloading packages from an account with a limited, poor reputation and had their environment variables and secrets compromised as a result. This emphasizes the importance of leveraging all of the metrics made available for open source packages before including them into projects,” McGuire adds. 

While it seems obvious by now that dependencies with security vulnerabilities should be excluded, McGuire says component provenance, health, and operational factors should also serve as inclusion criteria; those with little to no history concerning changes from one version to the next, questionable owners, poor community support, and suchlike, should be flagged for further review and scrutiny.  

This may sound like a time-consuming task, but there is no shortage of tools on the market that do this automatically and build directly into the software development lifecycle, McGuire ends. 

Mitigation Strategies for Developers 

Incidents such as this one emphasize the need for better security practices when using third-party packages from repositories like PyPI. Developers can protect themselves by: 

  • Verifying package authenticity: Check a package’s author, version history, and reviews before installing anything. 
  • Auditing dependencies: Use tools like pip-audit to pinpoint and remove potentially malicious packages. 
  • Monitoring environment variables: Store sensitive credentials in secure vaults instead of plaintext environment variables. 
  • Implementing supply chain security tools: Solutions like dependency scanning and runtime monitoring can help detect anomalies in installed packages. 
Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

What Are AI SOC Agents? Use Cases, Architecture, and the Leading Vendors

June 19, 20266 Mins Read

AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals

June 19, 20265 Mins Read

From AI hype to operational reality: A practitioner’s framework for securing agentic systems

June 5, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}