Shai-Hulud copycat campaign targets Python developers through PyPI typosquatting
about.gitlab.com | blog | #supply-chain | #malware | #credential-theft | #pypi | #python | #shai-hulud | #typosquatting
Summary
GitLab researchers found five malicious PyPI packages, including typosquats of Flask, Requests, and NumPy, that deploy the Shai-Hulud worm via .pth files to steal CI/CD credentials.
- Published
- Collected
Skip to content