Malicious 'Checker' Packages on PyPI Probe TikTok and Instagram for Valid

2 feross 1 5/15/2025, 10:31:11 PM socket.dev โ†—

Comments (1)

duskwuff ยท 9h ago
Calling libraries "malicious" and "malware" simply because they interact with web service APIs in an unauthorized way, or because they could potentially be used for nefarious purposes, is a pretty serious overstatement.

Would I use these libraries in an application I was writing? Probably not. But I don't see any evidence of malice here, like exfiltrating the usernames/passwords to a third party or executing code from an unexpected source. At best, these libraries are potentially unwanted, not malicious.