PyPI finds supply chain attacks active for more than half a year
The Python package repository PyPI was the target of a sophisticated supply chain attack in which at least two legitimate software packages were successfully implanted with credential-stealing malware, researchers from security firms SentinelOne and Checkmarx report . The attackers launched a phishing attack on Python developers, tricking them into revealing their login credentials, and then […]
PyPI finds supply chain attacks active for more than half a year Read More »