Top open source PyPI package with over 1 million downloads each month hacked to send out malware



  • A widely used PyPI package was recently compromised through a malicious update
  • The attack leveraged a GitHub Actions workflow to push infostealer code into a release
  • Maintainers quickly issued a clean version, rotated credentials, and began an external investigation

A popular Python Package Index (PyPI) package has been compromised and used to deliver malware to its users, experts have warned.

A user recently warned maintainers of the Elementary package that the newest version, 0.23.3, contained “malicious base64 encoded code”. The maintainers soon responded, confirming the news, releasing a clean update (0.23.4), and notifying other users.

https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH-750-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img