Sonatype uncovers further malicious PyPI and npm packages
Sonatype continues to uncover a significant number of malicious packages within the PyPI and npm software registries.
Among the flagged packages were several Python packages published on PyPI, masquerading as legitimate libraries named after the popular npm "colors" library.
The malicious packages, including names such as "broke-rcl," "brokescolors," and "trexcolors," exclusively targeted the Windows operating system. Once installed, these packages would initiate the...
Recent Comments