PyPI
- APPLICATIONS
Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data
Cybersecurity researchers have discovered a malicious package on the Python Package Index (PyPI) repository that’s capable of harvesting sensitive developer-related…
Read More » - APPLICATIONS
New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally
Cybersecurity researchers have flagged a supply chain attack targeting over a dozen packages associated with GlueStack to deliver malware. The…
Read More » - APPLICATIONS
Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks
Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets,…
Read More » - APPLICATIONS
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts
Cybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to…
Read More » - APPLICATIONS
Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads
î ‚May 13, 2025î „Ravie LakshmananSupply Chain Attack / Blockchain Cybersecurity researchers have discovered a malicious package on the Python Package Index…
Read More » - APPLICATIONS
Researchers Uncover Malware in Fake Discord PyPI Package Downloaded 11,500+ Times
î ‚May 07, 2025î „Ravie LakshmananSoftware Supply Chain / Malware Cybersecurity researchers have discovered a malicious package on the Python Package Index…
Read More » - APPLICATIONS
GCP Cloud Composer Bug Let Attackers Elevate Access via Malicious PyPI Packages
Cybersecurity researchers have detailed a now-patched vulnerability in Google Cloud Platform (GCP) that could have enabled an attacker to elevate…
Read More » - APPLICATIONS
Malicious PyPI Package Targets MEXC Trading API to Steal Credentials and Redirect Orders
î ‚Apr 15, 2025î „Ravie LakshmananSupply Chain Attack / Malware Cybersecurity researchers have disclosed a malicious package uploaded to the Python Package…
Read More » - APPLICATIONS
Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data
î ‚Apr 05, 2025î „Ravie LakshmananMalware / Supply Chain Attack Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI)…
Read More » - APPLICATIONS
Router Hacks, PyPI Attacks, New Ransomware Decryptor, and More
î ‚Mar 17, 2025î „Ravie LakshmananCybersecurity / Hacking News From sophisticated nation-state campaigns to stealthy malware lurking in unexpected places, this week’s…
Read More »