Huntbase Hub · All hunts

Threat hunts for PyPI

3 hunts covering PyPI, each with a hypothesis, the queries that test it and what the hunt cannot see.

3 hunts

  1. high Part 2 of 2
    Research by Sekoia

    ChocoPoC: Mapbox Dead-Drop C2 and Exfiltration

    An adversary is using trojanised Python packages to establish C2 via DoH and Mapbox datasets on researcher workstations, subsequently exfiltrating credentials from local password stores.

    3 query1 analytic1 checkpoint1 action2 task
    CVE-2025-55182 · CVE-2025-64446
  2. high
    Research by Elastic Security Labs

    Linux Fileless and In-Memory Execution

    An adversary is executing malicious code on Linux hosts by staging payloads in memory-backed file descriptors, using interpreter one-liners, or running unlinked binaries to avoid on-disk detection.

    5 query2 analytic1 checkpoint1 action2 task
    defense evasion · execution · initial access
  3. high
    Research by Microsoft

    IT Support Impersonation and WinRM Lateral Expansion

    An adversary has hijacked a remote-support session to execute PowerShell, use a portable Node.js runtime for C2, and expand laterally via WinRM to domain controllers.

    5 query2 analytic1 checkpoint1 action2 task
    command and control · discovery · execution