Phishing Campaign Targets PyPI Users to Distribute Malicious Code
The first-of-its-kind campaign threatens to remove code packages if developers don’t submit their code to a "validation" process.
Stay updated with breaking news from Python Package Index. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
The first-of-its-kind campaign threatens to remove code packages if developers don’t submit their code to a "validation" process.
Checkmarx has found that one in three software packages from PyPi contains a flaw that can lead to malicious content being installed.
The findings, discovered by Checkmarx and published Friday, underscore how open source software repositories like PyPi are increasingly being targeted and leveraged by malicious actors.
The scans used by the Python Package Index (PyPI) to find malware fail to catch 41% of bad packages, while creating plentiful false positives.
Just as one crop of malware-laced software packages is taken down from the popular Python code repository, a new host arrives, looking to steal a raft of data.