Tuesday, November 26, 2024

Python

Two PyPi Malicious Package Mimic ChatGPT & Claude Steals Developers Data

Two malicious Python packages masquerading as tools for interacting with popular AI models ChatGPT and Claude were recently discovered on the Python Package Index (PyPI), the official repository for...

Beware Of Malicious Python Packages That Steal Users Sensitive Data

Malicious Python packages uploaded by "dsfsdfds" to PyPI infiltrated user systems by exfiltrating sensitive data to a Telegram bot likely linked to Iraqi cybercriminals. Active...

Python Developers Beware! Russian Hackers Targeting You With Malicious Packages

A malicious Python package named "crytic-compilers" was identified on PyPI.Masquerading as a legitimate library for intelligent contract compilation, it mimicked the name and...

Malicious PyPI & NPM Packages Attacking MacOS Users

Cybersecurity researchers have identified a series of malicious software packages targeting MacOS users.These packages, found on the Python Package Index (PyPI) and NPM,...

170K+ Python Developers GitHub Accounts Hacked in Supply Chain Attack

Over 170,000 users have fallen victim to a meticulously orchestrated scheme exploiting the Python software supply chain.The Checkmarx Research team has uncovered a...

Beware of Typos that May lead to Malicious PyPI Package Installation

Cybersecurity experts have raised alarms over a new threat vector targeting Python developers: typo-squatting on the Python Package Index (PyPI).The notorious Lazarus group,...

Hackers Started using Python for Developing New Ransomware

Ransomware has been one of the top threats to organizations, contributing several millions of dollars to multiple organizations worldwide.Most of these ransomware operators...

3 New Malicious PyPI Packages Found Installing CoinMiner on Linux Devices

Researchers identified three malicious PyPI (Python Package Index) packages that deploy a CoinMiner executable on Linux devices, affecting latency in device performance.These packages, namely modular...

New Undetected Python-Based Info-stealer Offered Via Dedicated Website

Akira is an information stealer malware that was found in March 2023. This malware can steal sensitive information, including saved credentials and payment card...

Two Malicious Python Packages Steal SSH and GPG Keys Exists in the Python Package Index for a Year

The python security team has removed two malicious python packages that introduced with the Python Package Index (PyPI) aimed to steal SSH and GPG...

PyXie – A Python RAT Escalate The Windows Admin Privilege to Deliver Ransomware, MITM Attack, Keylogging & Steal Cookies

Researchers discovered a previously unknown fully-featured Python RAT called"PiXie" escalate the Windows admin privilege to the ransomware in the healthcare and education industries.PyXie initially...