Tagged: PyPI

Cross-platform sckit worm infection vector bridging npm and PyPI ecosystems via MemTensor packages 0

The ‘sckit’ Worm Bridges the npm and PyPI Divide

An identical, highly sophisticated malicious program has successfully breached both sides of a major programming language divide simultaneously. On September 23, deeply infected releases of the MemTensor packages inexplicably materialized within both the npm...

Dependabot update cooldown workflow protecting software supply chain security 0

Dependabot and PyPI Add Supply Chain Cooldowns

GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. Dependabot now enforces a mandatory three-day holding period by default,...

New Python Trojan “SilentSync” Found on PyPI

Experts from Zscaler ThreatLabz have uncovered two malicious packages in the PyPI repository that, upon installation and import, secretly deploy the SilentSync Python trojan—a threat capable of seizing control of developer environments and exfiltrating...