AWS keys stolen by malicious PyPI package with thousands of downloads




  • Researchers discover three-year old malicious package in PyPI
  • The package is a typosquatted version of Fabric, with 37,000 downloads
  • Its goal is to steal AWS login credentials from the developers

A malicious Python package has been hiding in the Python Package Index (PyPI) for years, stealthily stealing people’s Amazon Web Service (AWS) credentials.

Cybersecurity researchers Socket outlined how a package called “fabrice” was uploaded to the repository back in 2021 – before PyPl deployed its advanced scanning tool.

https://cdn.mos.cms.futurecdn.net/CBHUAsfrHYAci3MTWZBsgN-1200-80.png



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img