pypi Archives - Developer Tech News https://www.developer-tech.com/news/tag/pypi/ Gaming, Apps, HTML5, Java, PHP, C#, .net, IOT Mon, 14 Oct 2024 13:58:49 +0000 en-GB hourly 1 https://www.developer-tech.com/wp-content/uploads/2020/09/dev-icon-60x60.png pypi Archives - Developer Tech News https://www.developer-tech.com/news/tag/pypi/ 32 32 Entry points threaten multiple open-source ecosystems https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/ https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/#respond Mon, 14 Oct 2024 13:58:48 +0000 https://www.developer-tech.com/?p=46680 While current tools have improved at detecting common tactics for exploiting open-source packages, a feature remains largely overlooked: entry points. Security researchers at Checkmarx uncovered how attackers can leverage entry points across multiple programming ecosystems, with a particular focus on PyPI, to trick victims into running malicious code. This method – while not allowing for... Read more »

The post Entry points threaten multiple open-source ecosystems appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/entry-points-threaten-multiple-open-source-ecosystems/feed/ 0
Sonatype exposes malicious PyPI package ‘pytoileur’ https://www.developer-tech.com/news/sonatype-exposes-malicious-pypi-package-pytoileur/ https://www.developer-tech.com/news/sonatype-exposes-malicious-pypi-package-pytoileur/#comments Wed, 29 May 2024 15:19:27 +0000 http://www.developer-tech.com//?p=46038 Sonatype has exposed ‘pytoileur’, a malicious PyPI package designed to download and install trojanised Windows binaries capable of surveillance, commandeering persistence, and stealing cryptocurrency. This discovery is part of a broader, months-long “Cool package” campaign aimed at infiltrating the coding community. Yesterday, an automated malware detection system operated by Sonatype, known as the Sonatype Repository... Read more »

The post Sonatype exposes malicious PyPI package ‘pytoileur’ appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/sonatype-exposes-malicious-pypi-package-pytoileur/feed/ 1
Phylum uncovers targeted malware disguised in Python package https://www.developer-tech.com/news/phylum-uncovers-targeted-malware-disguised-python-package/ https://www.developer-tech.com/news/phylum-uncovers-targeted-malware-disguised-python-package/#respond Mon, 13 May 2024 12:11:15 +0000 http://www.developer-tech.com//?p=45989 Phylum’s cybersecurity experts have detected a malicious payload embedded within a popular Python package on the PyPI repository. The package, named requests-darwin-lite, is an unauthorised variant of the widely-used requests library. The requests-darwin-lite package was cleverly designed to emulate its legitimate counterpart but included a Go binary concealed within an oversized image file pretending to... Read more »

The post Phylum uncovers targeted malware disguised in Python package appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/phylum-uncovers-targeted-malware-disguised-python-package/feed/ 0
PyPI suspends registrations amid malware attack https://www.developer-tech.com/news/pypi-suspends-registrations-amid-malware-attack/ https://www.developer-tech.com/news/pypi-suspends-registrations-amid-malware-attack/#respond Thu, 28 Mar 2024 12:52:52 +0000 http://www.developer-tech.com//?p=45836 The Python Package Index (PyPI) has suspended new project creation and user registration to mitigate an ongoing malware upload campaign. This move comes as security researchers at Checkmarx uncovered a campaign involving multiple malicious packages related to the same threat actors. The attackers are targeting victims through typosquatting attacks, tricking users into installing malicious Python... Read more »

The post PyPI suspends registrations amid malware attack appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/pypi-suspends-registrations-amid-malware-attack/feed/ 0
Python packages caught using DLL sideloading to bypass security https://www.developer-tech.com/news/python-packages-dll-sideloading-bypass-security/ https://www.developer-tech.com/news/python-packages-dll-sideloading-bypass-security/#respond Wed, 21 Feb 2024 11:55:04 +0000 http://www.developer-tech.com//?p=45680 ReversingLabs researchers have uncovered Python packages using DLL sideloading to bypass security tools. On 10 January 2024, Karlo Zanki, a reverse engineer at ReversingLabs, stumbled upon two suspicious packages on the Python Package Index (PyPI). These packages – named NP6HelperHttptest and NP6HelperHttper – were found to be utilising DLL sideloading, a known technique used by... Read more »

The post Python packages caught using DLL sideloading to bypass security appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/python-packages-dll-sideloading-bypass-security/feed/ 0
Open source wins concessions in new EU cyber law https://www.developer-tech.com/news/open-source-wins-concessions-new-eu-cyber-law/ https://www.developer-tech.com/news/open-source-wins-concessions-new-eu-cyber-law/#respond Mon, 15 Jan 2024 12:18:32 +0000 http://www.developer-tech.com//?p=45528 The European Cyber Resilience Act (CRA) has undergone substantial revisions, bringing relief to the open-source community. Back in April, the Python Software Foundation (PSF) had expressed concerns about potential repercussions for CPython and PyPI if the initial form of CRA were to be enacted. The primary worry was that, in the course of providing open-source... Read more »

The post Open source wins concessions in new EU cyber law appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/open-source-wins-concessions-new-eu-cyber-law/feed/ 0
Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign https://www.developer-tech.com/news/malicious-pypi-package-ongoing-paperpin-campaign/ https://www.developer-tech.com/news/malicious-pypi-package-ongoing-paperpin-campaign/#respond Fri, 04 Aug 2023 11:05:45 +0000 http://www.developer-tech.com//?p=44995 In a recent analysis conducted by Sonatype, a malicious Python Package Index (PyPI) package named ‘VMConnect’ was discovered masquerading as the legitimate VMware vSphere connector module ‘vConnector’. The counterfeit package was found to contain sinister code designed to compromise users’ systems. Further investigation revealed an ongoing campaign involving additional packages like “ethter” and “quantiumbase,” all... Read more »

The post Malicious PyPI package discovered in ongoing ‘PaperPin’ campaign appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/malicious-pypi-package-ongoing-paperpin-campaign/feed/ 0
Sonatype uncovers further malicious PyPI and npm packages https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/ https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/#respond Fri, 23 Jun 2023 15:47:27 +0000 http://www.developer-tech.com//?p=44763 Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries. Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm “colors” library. The malicious packages, including names such as “broke-rcl,” “brokescolors,” and “trexcolors,” exclusively targeted the Windows operating... Read more »

The post Sonatype uncovers further malicious PyPI and npm packages appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/sonatype-uncovers-further-malicious-pypi-npm-packages/feed/ 0
PyPI suspends new projects and users due to malicious activity https://www.developer-tech.com/news/pypi-suspends-new-projects-and-users-malicious-activity/ https://www.developer-tech.com/news/pypi-suspends-new-projects-and-users-malicious-activity/#respond Mon, 22 May 2023 15:31:24 +0000 http://www.developer-tech.com//?p=44601 The PyPI (Python Package Index) team has temporarily suspended new projects and users on their platform due to malicious activity. This surge in malicious activity aligns with a larger trend observed across several open-source registries in recent months. Notably, incidents such as the flood of malicious packages on the NPM JavaScript package manager and a... Read more »

The post PyPI suspends new projects and users due to malicious activity appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/pypi-suspends-new-projects-and-users-malicious-activity/feed/ 0
PyPI will sell ‘Organization’ accounts to corporate projects https://www.developer-tech.com/news/pypi-sell-organization-accounts-corporate-projects/ https://www.developer-tech.com/news/pypi-sell-organization-accounts-corporate-projects/#respond Mon, 24 Apr 2023 14:49:43 +0000 http://www.developer-tech.com//?p=44491 Python Packaging Index (PyPI) has announced the introduction of ‘Organization’ accounts, as the first step in its plan to build financial support and long-term sustainability. Organizations on PyPI are self-managed teams with exclusive branded web addresses. PyPI aims to make its platform easier to use for large community projects, organisations, or companies that manage multiple... Read more »

The post PyPI will sell ‘Organization’ accounts to corporate projects appeared first on Developer Tech News.

]]>
https://www.developer-tech.com/news/pypi-sell-organization-accounts-corporate-projects/feed/ 0