Dad On Retire
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
Dad On Retire
No Result
View All Result
Home Editor's Pick

Software downloaded 30,000 times from PyPI ransacked developers’ machines

by
July 30, 2021
in Editor's Pick
0
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

Enlarge

Open source packages downloaded an estimated 30,000 times from the PyPI open source repository contained malicious code that surreptitiously stole credit card data and login credentials and injected malicious code on infected machines, researchers said on Thursday.

In a post, researchers Andrey Polkovnichenko, Omer Kaspi, and Shachar Menashe of devops software vendor JFrog said they recently found eight packages in PyPI that carried out a range of malicious activity. Based on searches on https://pepy.tech, a site that provides download stats for Python packages, the researchers estimate the malicious packages were downloaded about 30,000 times.

Systemic threat

The discovery is the latest in a long line of attacks in recent years that abuse the receptivity of open source repositories, which millions of software developers rely on daily. Despite their crucial role, repositories often lack robust security and vetting controls, a weakness that has the potential to cause serious supply chain attacks when developers unknowingly infect themselves or fold malicious code into the software they publish.

Read 14 remaining paragraphs | Comments

Previous Post

Feds list the top 30 most exploited vulnerabilities. Many are years old

Next Post

With help from Google, impersonated Brave.com website pushes malware

Next Post

With help from Google, impersonated Brave.com website pushes malware

Get the daily email that makes reading the news actually enjoyable. Stay informed and entertained, for free.
Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
  • Trending
  • Comments
  • Latest

VPN servers seized by Ukrainian authorities weren’t encrypted

July 26, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

Prebiotics consumption expands in food and beverage applications – key nutritional benefits drive the ingredient demand

June 11, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

The 40 Weirdest (And Best) Charts We Made In This Long, Strange Year

0

How U.S. Government Paper Currency Began, and How Private Banknotes Ended

0

Covid Inside Rural India

0

Reply to “Reply to Whitehead” by Desvousges, Mathews and Train: (4) My treatment of the weighted WTP is biased in favor of the DMT (2015) result/conclusion

0
Trump has not been notified whether Manhattan DA plans to bring charges: sources

Trump has not been notified whether Manhattan DA plans to bring charges: sources

March 22, 2023
Georgia senators advance bill allowing truck weight changes on highways

Georgia senators advance bill allowing truck weight changes on highways

March 22, 2023
DeSantis touts his potential to beat Biden if he runs for president: ‘I think he’s failed the country’

DeSantis touts his potential to beat Biden if he runs for president: ‘I think he’s failed the country’

March 22, 2023
North Carolina House advances ban on COVID-19 vaccine mandates

North Carolina House advances ban on COVID-19 vaccine mandates

March 22, 2023

Recent News

Trump has not been notified whether Manhattan DA plans to bring charges: sources

Trump has not been notified whether Manhattan DA plans to bring charges: sources

March 22, 2023
Georgia senators advance bill allowing truck weight changes on highways

Georgia senators advance bill allowing truck weight changes on highways

March 22, 2023
DeSantis touts his potential to beat Biden if he runs for president: ‘I think he’s failed the country’

DeSantis touts his potential to beat Biden if he runs for president: ‘I think he’s failed the country’

March 22, 2023
North Carolina House advances ban on COVID-19 vaccine mandates

North Carolina House advances ban on COVID-19 vaccine mandates

March 22, 2023

Disclaimer: DadOnRetire.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting

Copyright © 2022 DadOnRetire. All Rights Reserved.

No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock

Copyright © 2022 DadOnRetire. All Rights Reserved.