News
The past year has seen over 10,000 downloads of malicious packages hosted on the official Python package repository, ESET research finds.
The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking ...
PyApp seems to be taking the Python world by storm, providing long-awaited click-and-run Python distribution. For developers ...
Two malicious versions of two Python packages were introduced in the Python Package Index (PyPI) with the purpose of stealing SSH and GPG keys from Python developers' projects.
The method introduces another supply chain vulnerability for the future, as most security tools solely scan Python source code (PY) files, making them susceptible to missing such attacks. Zanki said ...
Over the weekend an attacker has been uploading thousands of malicious Python packages on the public PyPI (Python Package Index) software repository.
More than 400 malicious packages were recently uploaded to PyPI (Python Package Index), the official code repository for the Python programming language, in the latest indication that the ...
Microsoft harvested data about Python compatibility for libraries currently registered with PyPI (Python Package Index), the default repository for third-party Python libraries.
Devs unknowingly use “malicious” modules snuck into official Python repository Code packages available in PyPI contained modified installation scripts.
Nir Cohen describes Wagon, which takes Python wheels, packages them together, adds metadata, and allows for offline extraction and installation.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results