News
Developers who published projects on PyPI with their email in package metadata are being targeted They are asked to "verify" ...
According to the company, Insight Partners led the investment with participation from Mubadala Capital. Bloomberg reported ...
Furthermore, this package doesn’t even try to hide its true intentions, and instead is “openly malicious”. Despite being obvious malware, it still managed to rake in 37,217 downloads.
Sonatype analysts J. Cardona and C. Fernandez figured that the packages 'loglib-modules' and 'pygrata-utils' were created for data exfiltration, snatching AWS credentials, network interface ...
The latest such campaign was uncovered by researchers from ReversingLabs and involves malicious code hidden in compiled Python files (PYC) that were part of a fake test project given to job ...
This package, too, mimicked the name of a popular Python library, named "colorama." According to the PyPI Stats service, 54 users had downloaded the package a month before it was taken down.
Furthermore, this package doesn’t even try to hide its true intentions, and instead is “openly malicious”. Despite being obvious malware, it still managed to rake in 37,217 downloads.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results