Python PYTHONPATH Modification During Package Installation: endpointEndpointNoneversion:1
The following analytic detects modification of the PYTHONPATH environment variable in conjunction with a package installation process.
Python looks up the `sys.path` variable, which is generated by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment variable, to determine which directories to use for importing modules.
If an adversary is able to control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack imported packages, achieving user-level persistence across future Python invocations and new shell sessions.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked by the affected user.
Python Network Traffic During Package Build: endpointEndpointNoneversion:1
The following analytic detects a Python process making an outbound network connection during package installation.
Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
This activity is significant because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond running `pip install`.
If confirmed malicious, this could indicate a successful software supply chain compromise.
Python PTH File Creation During Package Installation: endpointEndpointNoneversion:1
The following analytic detects the creation of a Python path configuration (`.pth`) file in conjunction with a package installation process.
Path configuration files placed under `site-packages` or `dist-packages` are executed with every subsequent invocation of Python, allowing adversaries to achieve persistence on the victim endpoint regardless of build method or distribution type.
This technique was used by the threat actor group TeamPCP during the supply chain compromise of the `litellm` package.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.
Python Site Hooks Creation During Package Installation: endpointEndpointNoneversion:1
The following analytic detects the creation of a Python site hook file (`sitecustomize.py` or `usercustomize.py`) within a `site-packages`/`dist-packages` directory in conjunction with a package installation process.
Python's `site` module loads these hooks from directories on `sys.path` before Python is executed.
If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint.
The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.