• Security researchers found two packages on PyPI, showing malicious intent
  • The packages grant the attackers access to systems and sensitive data
  • The researchers warn developers to exercise caution when using third-party packages

Experts have warned PyPI continues to be abused after researchers discovered more malicious packages hiding on the platform.

A report from Fortinet’s FortiGuard Labs discovered two packages designed to steal people’s login credentials, grant unauthorized access to devices, and more.



Source link

Podcast also available on PocketCasts, SoundCloud, Spotify, Google Podcasts, Apple Podcasts, and RSS.