PyPI contributors targeted by JuiceLedger in latest attack against open source
Cybersecurity News
Stay updated with breaking news from Python Package Index. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Cybersecurity News
The phishing-as-a-service offering targets accounts from tech giants, and also has connections to PyPI phishing and the Twilio supply chain attack.
Researchers have identified a new hacking group "JuiceLedger" behind the first known phishing campaign targeting the Python Package Index.
PyPI, the Python Package Index, automatically executes code on the system when developers merely download a package.
"JuiceLedger" has escalated a campaign to distribute its information stealer by now going after developers who published code on the widely used Python code repository.