PyPI

11 Malicious PyPI Python Libraries Caught Stealing Discord Tokens and Installing Shells

Cybersecurity researchers have uncovered as many as 11 malicious Python packages that have been cumulatively downloaded more than 41,000 times… Read More

3 years ago

PyPI removes 'mitmproxy2' over code execution concerns

The PyPI repository has removed a Python package called 'mitmproxy2' that was an identical copy of the official "mitmproxy" library,… Read More

3 years ago

Supply Chain Attacks via Open-Source Repositories Spike

A report from Sonatype revealed that supply chain attacks on open-source public repositories have increased up to 650% year-over-year. The… Read More

3 years ago

Researchers Unearth Logic Bomb Attack in Python Package Index (PyPI)

The researchers found six malicious payloads, all uploaded by a single user. The attacker designed them to run during a… Read More

3 years ago

Several Malicious Typosquatted Python Libraries Found On PyPI Repository

As many as eight Python packages that were downloaded more than 30,000 times have been removed from the PyPI portal… Read More

3 years ago

Python team fixes bug that allowed takeover of PyPI repository

The Python security team has fixed today three vulnerabilities impacting the Python Package Index (PyPI), including one that could have… Read More

3 years ago

Eight Malicious Typosquatted Python Libraries with Over 30,000 Downloads Found On PyPI Repository

The packages could be abused to execute remote code, amass system information, steal credit card information and passwords auto-saved in… Read More

3 years ago