More

    AWS keys stolen by malicious PyPI package with thousands of downloads




    • Researchers discover three-year old malicious package in PyPI
    • The package is a typosquatted version of Fabric, with 37,000 downloads
    • Its goal is to steal AWS login credentials from the developers

    A malicious Python package has been hiding in the Python Package Index (PyPI) for years, stealthily stealing people’s Amazon Web Service (AWS) credentials.

    Cybersecurity researchers Socket outlined how a package called “fabrice” was uploaded to the repository back in 2021 – before PyPl deployed its advanced scanning tool.

    https://cdn.mos.cms.futurecdn.net/CBHUAsfrHYAci3MTWZBsgN-1200-80.png



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img