The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking accounts through password resets. PyPI is the official repository for open-source Python packages. It …
PyPI
-
-
Security
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
by Wikdailyby WikdailyCybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a dependency that allows it to establish persistence and achieve code …
-
Security
Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets
by Wikdailyby WikdailyA malicious Python package posing as a harmless add-on for the Chimera sandbox environment, an integrated machine learning experimentation and development tool, is helping threat actors steal sensitive corporate credentials. …
-
Security
Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data
by Wikdailyby WikdailyCybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that’s capable of harvesting sensitive developer-related information, such as credentials, configuration data, and environment variables, among …
-
Security
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally
by Wikdailyby WikdailyCybersecurity researchers have flagged a supply chain attack targeting over a dozen packages associated with GlueStack to deliver malware. The malware, introduced via a change to “lib/commonjs/index.js,” allows an attacker …
-
Security
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks
by Wikdailyby WikdailySeveral malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets, erase entire codebases after installation, and exfiltrate Telegram API tokens, …