Tagged: PyPI

The Math Malware: How “sympy-dev” Hijacked PyPI to Mine Crypto

A malicious software package masquerading as a ubiquitous library for symbolic mathematics has been identified within the official PyPI repository. Orchestrators of this campaign meticulously replicated the description of the legitimate project to present...

New Python Trojan “SilentSync” Found on PyPI

Experts from Zscaler ThreatLabz have uncovered two malicious packages in the PyPI repository that, upon installation and import, secretly deploy the SilentSync Python trojan—a threat capable of seizing control of developer environments and exfiltrating...