Malware campaign targets official Python and JavaScript repos
An active malware campaign is targeting official Python and JavaScript repositories.
Software supply chain security firm Phylum spotted the campaign. Phylum said that it discovered the campaign after noticing a flurry of activity around typosquats of the popular Python requests package.
Typosquats take advantage of simple typos to install malicious packages.
In this case, the PyPI typos include: dequests, fequests, gequests, rdquests, reauests, reduests,...
Recent Comments