Warning: session_start(): open(/opt/alt/php82/var/lib/php/session/sess_jsdla3jl2dm6eslsct70vdisgi, O_RDWR) failed: Disk quota exceeded (122) in /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/social-auto-poster/social-auto-poster.php on line 508

Warning: session_start(): Failed to read session data: files (path: /opt/alt/php82/var/lib/php/session) in /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/social-auto-poster/social-auto-poster.php on line 508
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets - WikDaily
Home » Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

by Wikdaily
0 comments
Hacker


A malicious Python package posing as a harmless add-on for the Chimera sandbox environment, an integrated machine learning experimentation and development tool, is helping threat actors steal sensitive corporate credentials.

According to new research findings from software supply chain and DevOps company JFrog, the package “chimera-sandbox-extensions”, recently uploaded to the popular PyPI repository, contains a stealthy, multi-stage info-stealer.

“The detection of harmful packages, such as chimera-sandbox extensions, on PyPI highlights the significant and widespread risk posed by software supply chain attacks,” said Eric Schwake, director of Cybersecurity Strategy at Salt Security. “The primary threat lies in its ability to collect sensitive developer-related data, including credentials, configuration files, and especially AWS tokens and CI/CD environment variables.”

This poses a direct risk to corporate and cloud infrastructures, enabling attackers to maliciously access and possibly alter or steal large volumes of data through compromised API credentials, Schwake added.

You may also like

Leave a Comment

Welcome to WikDaily, your trusted source for the latest news, trends, and insights across the globe. We are a dynamic blog-style news platform committed to delivering fast, accurate, and engaging content across a variety of topics—from breaking headlines to deep dives into tech, business, entertainment, travel, sports, and more.

Edtior's Picks

Latest Articles

wikdaily 2025. Designed and Developed by Pro


Fatal error: Uncaught ErrorException: md5_file(/home/u968162543/domains/wikdaily.com/public_html/wp-content/litespeed/css/e84f433db344dc9ed92e0c49c9ab31f8.css.tmp): Failed to open stream: No such file or directory in /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimizer.cls.php:149 Stack trace: #0 [internal function]: litespeed_exception_handler() #1 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimizer.cls.php(149): md5_file() #2 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimize.cls.php(837): LiteSpeed\Optimizer->serve() #3 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimize.cls.php(333): LiteSpeed\Optimize->_build_hash_url() #4 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimize.cls.php(264): LiteSpeed\Optimize->_optimize() #5 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimize.cls.php(225): LiteSpeed\Optimize->_finalize() #6 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/class-wp-hook.php(324): LiteSpeed\Optimize->finalize() #7 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/plugin.php(205): WP_Hook->apply_filters() #8 /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/core.cls.php(459): apply_filters() #9 [internal function]: LiteSpeed\Core->send_headers_force() #10 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/functions.php(5471): ob_end_flush() #11 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/class-wp-hook.php(324): wp_ob_end_flush_all() #12 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/class-wp-hook.php(348): WP_Hook->apply_filters() #13 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/plugin.php(517): WP_Hook->do_action() #14 /home/u968162543/domains/wikdaily.com/public_html/wp-includes/load.php(1304): do_action() #15 [internal function]: shutdown_action_hook() #16 {main} thrown in /home/u968162543/domains/wikdaily.com/public_html/wp-content/plugins/litespeed-cache/src/optimizer.cls.php on line 149