PyPI Users Targeted With 'Wacatac' Trojan in New Supply Chain Attack
Three packages recently uploaded to PyPI contain code designed to fetch the Wacatac trojan and information stealer as a next stage payload.
Stay updated with breaking news from Python Package Index. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Three packages recently uploaded to PyPI contain code designed to fetch the Wacatac trojan and information stealer as a next stage payload.
The FortiGuard Labs team discovered an attack embedded in three PyPI packages called ‘colorslib’, ‘httpslib’, and “libhttps”. Read our blog to learn more.
Sigstore is an open source project launched by Linux Foundation with the goal of providing free and stable services for all developers to easily sign, verify and protect their software projects. While code signing is a valuable tool to prevent hackers from co-opting patching systems and delivering malware, it is difficult to implement in open source projects given the complexity of key management.
The FortiGuard Labs team has discovered a new 0-day attack embedded in three PyPI packages called 'colorslib', 'httpslib', and "libhttps". They were found on January 10, 2023, by... | January 14, 2023
ESET Research releases IPyIDA 2.0, a Python plugin integrating IPython and Jupyter Notebook into IDA to help researchers solve reverse engineering problems.