Malicious PyPi Package “automslc” Hits Sour Note with 100K Downloads: Deezer Piracy Scandal Unplugged

The malicious PyPi package automslc, downloaded over 100,000 times, sneaks into Deezer, pirating music using hardcoded credentials. It cleverly bypasses restrictions, raising piracy to an art form—but one that could land you in hot water. Remember, illegal downloads might not just cost you your playlist, but possibly your peace of mind!

Hot Take:

Looks like someone forgot to hit the pause button on ethics! A software package named “automslc” is rocking the boat by pirating music from Deezer using hard-coded credentials. It’s like the Napster of the Python world, only sneakier and potentially more dangerous. Who knew your love for streaming could get you into so much trouble?

Key Points:

– The automslc package has been downloaded over 100,000 times since 2019 from PyPi.
– It uses hard-coded Deezer credentials to pirate music and scrape metadata.
– The package can be repurposed for other malicious activities, posing security risks.
– Alias identities “hoabt2” and “Thanh Hoa” are linked to the package, but their true identities remain unknown.
– The tool’s C2 infrastructure suggests active monitoring, making it more than just a simple piracy tool.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here