Tagged: Typosquatting

RubyGems and npm package typosquatting attack deploying StubMaker stealer 0

Typosquatting Attack Strikes RubyGems and npm

Malicious actors brazenly targeted developers utilizing counterfeit packages deployed simultaneously across two highly prominent repositories. Cybercriminals stealthily introduced 16 malicious libraries into RubyGems and strategically placed another 37 within the npm registry. They meticulously...

New Python Trojan “SilentSync” Found on PyPI

Experts from Zscaler ThreatLabz have uncovered two malicious packages in the PyPI repository that, upon installation and import, secretly deploy the SilentSync Python trojan—a threat capable of seizing control of developer environments and exfiltrating...