Table of Contents
- The Allure of “Free” in a Pay-to-Play AI World
- The JarkaStealer Campaign: “gptplus” and “claudeai-eng”
- The Human Element: Our Greatest Vulnerability and Strongest Asset
- The Scope and Impact of the Threat
- Rethinking Our Approach to Cybersecurity
- How Organizations Should Approach Building Resilience in the AI Era
In the world of tech, FOMO isn’t just for social media anymore. AI FOMO is driving developers to make some alarmingly risky moves as they rush to harness the power of generative AI. Two innocent-looking Python packages, “gptplus” and “claudeai-eng,” masquerading as free APIs for popular AI chatbots, have been secretly spreading the JarkaStealer malware. This malware can turn the promise of innovation into a nightmare of data theft.
This deceptive campaign not only exploits the excitement surrounding AI but also exposes a critical vulnerability in our approach to cybersecurity – one that goes beyond technology and strikes at the heart of human behavior.
I’ve seen my fair share of cyber manipulation. However, the current frenzy surrounding generative AI presents a unique and potentially dangerous landscape for organizations and their employees. This recent discovery shows how cybercriminals exploit human behavior and emerging AI technologies.
The Allure of “Free” in a Pay-to-Play AI World
Access to cutting-edge language models often comes with a price tag. This creates a perfect storm for cybercriminals to exploit the enthusiasm and, sometimes, the desperation of developers eager to harness these powerful tools. This economic reality allows malicious actors to dangle the carrot of free access, knowing that some will bite without considering the potential consequences.

The JarkaStealer Campaign: “gptplus” and “claudeai-eng”
The attack vector in this case is as clever as it is concerning. Two Python packages, “gptplus” and “claudeai-eng,” were published on the Python Package Index (PyPI), promising free API access to OpenAI’s GPT-4 Turbo and Anthropic’s Claude. In reality, these packages delivered JarkaStealer, a relatively new but potentially devastating piece of malware.
What makes this attack particularly dangerous is the effort invested in creating a facade of legitimacy. The packages provide a rudimentary interaction with a free demo version of ChatGPT, giving users the illusion of functionality. This extra step in the deception process highlights the sophistication of modern cyber threats and the challenges organizations face in protecting their digital assets.
Download: Traditional Security Awareness vs Human Risk Management
Traditional Security Awareness doesn’t do the job anymore. Download our guide to see how HRM upgrades your program and takes Security Awareness into your larger cybersecurity goals.

The Human Element: Our Greatest Vulnerability and Strongest Asset
This incident underscores a truth that we at Right-Hand Cybersecurity have long emphasized: human behavior is at the heart of cybersecurity. The success of this campaign relies not on sophisticated technical exploits but on understanding and manipulating human psychology. Developers, driven by excitement over new technology and pressure to innovate quickly, may bypass crucial security checks.
Moreover, the attackers demonstrated an understanding of how security professionals evaluate package safety. By inflating download numbers, they exploited the common advice to check a package’s popularity before use. This manipulation of trust metrics clearly shows that we must constantly evolve our security practices to stay ahead of threat actors.
The Scope and Impact of the Threat
While the exact number of affected systems remains unclear, with each package downloaded over 1,700 times across more than 30 countries, the potential for data loss and system compromise is significant. JarkaStealer, despite it being relatively new, possesses capabilities typical of modern infostealers, including data theft, screenshot capture, and session token theft from popular applications.
The widespread availability of JarkaStealer’s source code on GitHub adds another layer of concern. This accessibility not only lowers the barrier to entry for potential attackers but also increases the likelihood of the malware evolving and spreading rapidly.
Rethinking Our Approach to Cybersecurity
I strongly believe that traditional, technology-focused security measures are no longer sufficient. We need a paradigm shift that places human behavior at the center of our cybersecurity strategies. We need to move beyond periodic, one-size-fits-all security awareness training to a more dynamic, personalized approach that adapts to individual user behaviors and risk profiles.
Furthermore, we must foster a security culture that encourages skepticism and careful vetting, even when dealing with seemingly trustworthy sources like official package repositories. The JarkaStealer campaign clearly shows that threat actors are willing to play the long game, maintaining a facade of legitimacy for extended periods to maximize their impact.
How to defend against phishing attacks?
Visit our page to find out what are end-to-end phishing defense and what are its components.

How Organizations Should Approach Building Resilience in the AI Era
As AI continues to reshape the tech, we can expect to see more sophisticated attacks that leverage both the tech itself and the hype surrounding it. To build resilience against these evolving threats, organizations need to:
- Implement robust vetting processes for third-party packages and APIs, especially those related to emerging technologies.
- Develop and maintain a security-aware culture that encourages employees to question and verify before acting.
- Invest in ongoing, adaptive security training that evolves with the threat landscape.
- Establish clear protocols for integrating new technologies, balancing innovation with security considerations.
The JarkaStealer campaign reminds us that in the rush to embrace new AI tech, we must not lose sight of fundamental security principles. By focusing on the human element of cybersecurity and fostering a culture of vigilance and continuous learning, we can harness the power of AI while mitigating its associated risks.
At Right-Hand Cybersecurity, we strongly believe that our greatest defense against cyber threats isn’t just in our technology – it’s in our people. By empowering employees with the knowledge and tools to recognize and respond to threats, we can build more secure organizations.



