National Cyber Warfare Foundation (NCWF)

Malicious PyPI Packages Stole Cloud Tokens Over 14,100 Downloads Before Removal


0 user ratings
2025-03-18 17:04:35
milo
Blue Team (CND)
Cybersecurity researchers have warned of a malicious campaign targeting users of the Python Package Index (PyPI) repository with bogus libraries masquerading as "time" related utilities, but harboring hidden functionality to steal sensitive data such as cloud access tokens.
Software supply chain security firm ReversingLabs said it discovered two sets of packages totaling 20 of them. The packages



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/malicious-pypi-packages-stole-cloud.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.