Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting

Summary

GitLab researchers found five malicious PyPI packages, including typosquats of Flask, Requests, and NumPy, that deploy the Shai-Hulud worm via .pth files to steal CI/CD credentials.
Published
Collected

original ↗

Related coverage

back