#pypi

[ follow ]
Information security
fromThe Hacker News
1 day ago

Fake Python Spellchecker Packages on PyPI Delivered Hidden Remote Access Trojan

Two malicious PyPI packages disguised as spellcheckers delivered a Python RAT via a base64 payload hidden in a Basque dictionary file.
Information security
fromThe Hacker News
1 week ago

Malicious PyPI Package Impersonates SymPy, Deploys XMRig Miner on Linux Hosts

A malicious PyPI package impersonating SymPy installs an XMRig cryptocurrency miner on Linux by downloading and executing ELF payloads in memory.
#python
Python
fromPython Software Foundation Blog
1 month ago

Sovereign Tech Agency and PSF Security Partnership

Investment improves CPython and PyPI security and reliability via archive-module fuzz-testing and OAuth/OIDC-based verified account recovery, enhancing supply chain resilience and user experience.
fromThe Hacker News
2 months ago

Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packages

"The scripts automate the process of downloading, building, and installing the required libraries and tools," security researcher Vladimir Pezo said. "Specifically, when the bootstrap script is executed, it fetches and executes an installation script for the package Distribute from python-distribute[.]org - a legacy domain that is now available for sale in the premium price range while being managed to drive ad revenue."
Information security
Python
fromPythonbytes
3 months ago

Python++

New Python ecosystem tools and projects include PyPI+ for package exploration, uv-ship for safer releases, performance analysis of Python 3.14, and the experimental Air framework.
fromThe Hacker News
3 months ago

Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown

JFrog said in an analysis. The executable ("_AUTORUN.EXE") is a compiled Go file that, besides including a SOCKS5 implementation as advertised, is also designed to run PowerShell scripts, set firewall rules, and relaunch itself with elevated permissions. It also carries out basic system and network reconnaissance, including Internet Explorer security settings and Windows installation date, and exfiltrates the information to a hard-coded Discord webhook.
Information security
fromRealpython
4 months ago

Astral's ty Type Checker for Python Quiz - Real Python

In this quiz, you'll revisit the key concepts from Astral's ty: A New Blazing-Fast Type Checker for Python. You'll check your understanding of installing ty from PyPI, running type checks, and interpreting its structured diagnostics. You'll also recall how to configure and silence specific rules, limit the scope of checks, and adjust Python version or platform settings. By completing this quiz, you'll cement your ability to experiment confidently with ty in personal or exploratory projects.
Python
#phishing
fromThe Hacker News
4 months ago

SilentSync RAT Delivered via Two Malicious PyPI Packages Targeting Python Developers

"SilentSync is capable of remote command execution, file exfiltration, and screen capturing," Zscaler ThreatLabz's Manisha Ramcharan Prajapati and Satyam Singh said. "SilentSync also extracts web browser data, including credentials, history, autofill data, and cookies from web browsers like Chrome, Brave, Edge, and Firefox." The packages, now no longer available for download from PyPI, are listed below. They were both uploaded by a user named "CondeTGAPIS."
Information security
fromThe Hacker News
5 months ago

PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain Attacks

These changes improve PyPI's overall account security posture, making it harder for attackers to exploit expired domain names to gain unauthorized access to accounts.
Python
fromArs Technica
6 months ago

Supply-chain attacks on open source software are getting out of hand

Malicious packages published on npm and PyPI had been downloaded more than 56,000 times, containing malware that enabled keylogging and other surveillance functionalities.
Privacy technologies
Growth hacking
fromThe Hacker News
8 months ago

Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts

Malicious packages on PyPI were designed to validate stolen emails against TikTok and Instagram, enabling potential cyber attacks.
[ Load more ]