๐ฐ Python Package Index News
Page 8 - Python Package Index News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Python Package Index. Real-time updates on events, politics, business and more.
January 3, 2023
Developers using the open-source package PyTorch machine learning framework may have downloaded a compromised version of the package from the PyPI repository over the holidays. The PyTorch team warns those who downloaded and installed PyTorch-nightly on Linux via pip between December 25, 2022 and December 30, 2022, should uninstall it and torchtriton immediately. They should
January 3, 2023
A rogue packet on the machine learning framework allowed the attacker to exfiltrate data, including SSH keys.
January 3, 2023
PyTorch open source framework installs malicious code after a dependencyโs PyPI code repository was compromised.
January 2, 2023
Python developers who spent some time coding over the holiday break may want to check out an advisory regarding a malicious PyTorch package that was being fetched from PyPI last week.
January 1, 2023
An open source machine learning framework that accelerates the path from research prototyping to production deployment.
December 19, 2022
A fully functional SentinelOne client is actually a Trojan horse that hides malicious code within; it was found lurking in the Python Package Index repository ecosystem.
December 5, 2022
Attacks on open-source and commercial software will continue to rise in 2023, says a new security vendor report on the software supply chain. However, the authors of the report also believe that the increased security measures developers are taking -- particularly on open source platforms like Github, NPM, RubyGems and PyPI -- may slow that
December 1, 2022
Days after researchers for Phylum and Checkmarx revealed an ongoing software supply chain attack spreading the W4SP Stealer malware through malicious packages on the Python Package Index (PyPI), ReversingLabs researchers discovered 10 additional PyPI packages pushing modified versions of W4SP that were overlooked.
November 29, 2022
Here's a comprehensive look at some of the lesser-known, but no less serious, types of software supply chain attacks.
November 4, 2022
Threat actors continue to push malicious Python packages to the popular PyPI service, striking with typosquatting, authentic sounding file names, and hidden imports to fool developers and steal their information.