10 Malicious Code Packages Slither into PyPI Registry
The discovery adds to the growing list of recent incidents where threat actors have used public code repositories to distribute malware in software supply chain attacks.
Source: darkreading.com
Stay updated with breaking news from Python Package Index. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
The discovery adds to the growing list of recent incidents where threat actors have used public code repositories to distribute malware in software supply chain attacks.
Victims are offered the decryption key without payment, but the prank demonstrates how easy such an attack can be
The malware packages had names that were common typosquats of a legitimate widely used Python library. One was downloaded hundreds of times.
Google is providing Titan Security Keys to maintainers of projects in top 1% of downloads