Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

PyPl suspends new projects and user sign-ups following flood of malware

  • May 22, 2023
Total
0
Shares
0
0
0


The world’s biggest repository for open-source Python packages, PyPI, disabled new user registrations, and barred existing users from uploading new projects over the weekend, citing an unmanageable flood of malicious code being uploaded to the platform.

In an announcement posted on the PyPI status page, the organization said: “The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability to respond to it in a timely fashion, especially with multiple PyPI administrators on leave.”

The team planned to “re-group over the weekend” and soon enough, on Sunday evening (around 10 PM UTC), the suspension was lifted.

Supply chain attacks

Supply chain attacks are all the rage these days, and as a result, open-source repositories have become an attractive target for cybercriminals and hackers. These days, most companies are incorporating open-source software in their products, at least to some extent. By squeezing malicious packages into the repository, threat actors are hoping IT teams will pick it up, compromising not just the product they’re building, but their entire network and infrastructure. 

Most of the time, malicious actors would engage in “typosquatting” – creating malicious packages with names almost identical to already existing, benign packages. That way, they’re hoping that reckless, overworked, or understaffed developers won’t notice the difference and will pick the wrong package for their solution.

To build out credibility and have more people download their malware, threat actors would also generate fake reviews and blow up their download numbers with the help of bots and artificial intelligence.

In recent months, the attacks on Python developers through PyPI have intensified, and we have reported at least six separate incidents that were discovered this year .

Hackers are usually looking to install infostelaers, which help them steal credentials and access valuable company assets. 


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • News

That ChatGPT iPhone app has serious privacy issues you need to know about

  • May 22, 2023
View Post
Next Article
  • News

How to win the Memorial Day mattress sales: 4 tips to help you save

  • May 22, 2023
View Post
You May Also Like
View Post
  • News

The Witcher season 3: release date, trailer, cast, plot, and more

  • May 30, 2023
View Post
  • News

6 new Netflix Original movies and shows you can’t miss in June

  • May 30, 2023
View Post
  • News

Google confirms it’s been working on a another foldable but it’s not ready “yet”

  • May 30, 2023
View Post
  • News

Corsair introduces iCUE Link to make building your next PC easier

  • May 30, 2023
View Post
  • News

Windows 11 23H2 update is real, we’re told – but it could disappoint

  • May 30, 2023
View Post
  • News

iFi’s iCan Phantom is a beast of a headphone amp for the fussiest of cans

  • May 30, 2023
View Post
  • News

Microsoft gets defensive and reminds users how great Windows 11 is

  • May 30, 2023
View Post
  • News

Microsoft’s latest Windows 11 mishap causes havoc with AMD graphics cards

  • May 30, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.