#pypi 検索結果
🚨 We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

#OceanLotus #APT32 #PyPi uuid32_utils-1.x.x-py3-none-win32.whl cf3f59e2c4c8767697ea46475171697c 91a476fea45abc8b208e0a9e3293f774 a7a0add66b205967562c1fa9643b8421 22538214a3c917ff3b13a9e2035ca521 02f4701559fc40067e69bb426776a54f 5598baa59c716590d8841c6312d8349e Backward.dll…



I was annoyed of having to write README files for my projects. So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨ It creates a comprehensive README based on your project. Check it out on #PyPI and #npm


How do you optimize package delivery for 950,000+ Python developers? Check out how we're using Individual Provider Anycast to power platforms like @PyPI, where small improvements × billions of requests = massive impact! fastly.com/blog/powering-… #fastforward #pypi

🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages. Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

⚠️🧵 RL threat researchers detected an impersonation attempt targeting a popular #PyPI cloudscraper package with more than 50M downloads. It has the suffix "safe" added, but it is all but safe: secure.software/pypi/packages/…

PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain dlvr.it/TMkqLV #PyPI #Phishing #CyberSecurity #EmailScam #Python

파이썬 개발자 가짜 PyPI 사이트 피싱 사기 주의 wezard4u.tistory.com/429604 #파이썬 #pypi #피싱
This is done by Termspark 🔥 Text blink, italic text and more styles support on next release (1.7.0) Wait for it! #python #pypi #opensource
It's been a busy day for us! ⚠️🧵 RL's automated detection system flagged a new malicious #PyPI package: secure.software/pypi/packages/… While name would suggest this is a ChatGPT related project, it actually contains a #malware loader.

🎉 ActiveState is pleased to announce our inclusion as a Trusted Publisher to PyPI, enabling Python authors to securely publish Python packages directly via ActiveState’s Platform. Become a trusted author today: ow.ly/Z34i50RikiO #ActiveState #TrustedPublisher #PyPI
"Fake recruiter coding tests target devs with malicious Python packages" published by ReversingLabs. #Lazarus, #PyPI, #VMConnect, #DPRK, #CTI reversinglabs.com/blog/fake-recr…
A new supply chain attack on PyPI is delivering SilentSync, a Python RAT. The malware steals credentials and files from developers' systems. #PyPI #SupplyChainAttack #Python #Malware #Cybersecurity securityonline.info/pypi-under-att…
"揭秘APT-C-26(Lazarus)组织利用PyPI对Windows、Linux和macOS平台的攻击行动" published by Qihoo360. #APT-C-26, #PyPI, #CTI, #OSINT, #LAZARUS mp.weixin.qq.com/s?__biz=MzUyMj…
🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages. Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

"This attack technique involves hijacking PyPI software packages by manipulating the option to re-register them once they're removed from #PyPI's index by the original owner," JFrog security researchers Andrey Polkovnychenko & Brian Moussalli Learn more: jfrog.co/4cSgBOK

🪝 The Python Software Foundation (PSF) warns developers of phishing emails leading to a fake #PyPI login site designed to steal account credentials. Read: hackread.com/psf-warn-fake-… #CyberSecurity #Phishing #Python #Developers #InfoSec
#npm, #PyPI, and #RubyGems Packages Found Sending #Developer Data to #Discord Channels ift.tt/STKr63H

🎉 Launched my first package on #PyPI C-based HTTP client for #Python that mimics browser #fingerprint to bypass SSL blocks. ✅ Python 3.8-3.14 ✅ Linux, Windows, macOS ✅ 270 test cases ✅ requests compatible PyPI: pypi.org/project/httpmo… Github: github.com/arman-bd/httpm…

Just a little note for anyone interested... Running ```pip-audit``` revealed a #vulnerability in pip25.2 with no #PyPI database update available yet. The immediate fix is a manual patch update to pip 25.3.dev0 - #Development version. #python #python3 #pip #pip3 #pipx #security
Don't be surprised if you have crashing issues with xformers 0.0.33.dev1085. Stick to the dev1083 release for now, would be my recommendation, unless you know better. #xformers #Python #pypi #PythonLibraries #Attention #GenerativeAI #AIcoding
🚨 A malicious #PyPI package, #soopsocks, has already infected 2,600+ systems. Get the breakdown on how it works, the red flags to watch for, and steps to prevent similar #SoftwareSupplyChain threats, research powered by JFrog. 🔗 Learn more: bit.ly/48dS1cx
The malicious PyPI package SoopSocks masqueraded as a SOCKS5 proxy but secretly installed a Go-based backdoor with SYSTEM privileges, leaking system data to a Discord webhook. #SoopSocks #PyPI #SupplyChain #Backdoor #Cybersecurity securityonline.info/backdoor-disgu…
🚨 Developers, a malicious PyPI package 'soopsocks' infected over 2,600 systems before being taken down! Check your dependencies and stay vigilant against supply chain attacks. #PyPI #Cybersecurity thehackernews.com/2025/10/alert-…
thehackernews.com
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown
Malicious PyPI package soopsocks downloaded 2,653 times before takedown, exfiltrating Windows data to Discord.
The #HuggingFace hosted models are added to the 🦉🫥 PDF Anonymizer (see the #PyPi pdf-anonymizer-cli). I'm adding more LLM options. #anonymizer
🚨 Alert: Malicious PyPI package soopsocks infected 2,653 systems before takedown. Python developers, update & audit dependencies now! ⚠️ #CyberSecurity #PyPI #Malware #SupplyChainAttack

Malicious PyPI package `soopsocks` infected 2,653 Windows systems with backdoors disguised as a SOCKS5 proxy. Takedown initiated! 🚨 thehackernews.com/2025/10/alert-… #PyPI #Malware #Cybersecurity #Soopsocks #WindowsSecurity
thehackernews.com
Alert: Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown
Malicious PyPI package soopsocks downloaded 2,653 times before takedown, exfiltrating Windows data to Discord.
Malicious #PyPI package #soopsocks (2,653 downloads) posed as a SOCKS5 proxy but deployed a Go executable with PowerShell payloads. It modified firewall rules, established persistence, and exfiltrated data via a Discord webhook.

🚀 Just published my Python package django-template-integrator==1.0.1 on PyPI! One command to auto-integrate HTML templates into Django (templates/ & static/). Save hours of setup! 👉 pip install django-template-integrator==1.0.1 #Django #Python #PyPI
Аналитики Python Software Foundation зафиксировали новую волну фишинга, нацеленного на пользователей и мейнтейнеров PyPI - популярного репозитория для Python-пакетов: securitymedia.org/news/fishingov… #Python #Software #PyPI #infosecurity #CyberMedia

🚨 PSA for developers! The PSF warns of a convincing fake PyPI login site designed to steal your credentials. Always double-check URLs before logging in! #PyPI #CyberSecurity hackread.com/psf-warn-fake-…
🚨 We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.…

#OceanLotus #APT32 #PyPi uuid32_utils-1.x.x-py3-none-win32.whl cf3f59e2c4c8767697ea46475171697c 91a476fea45abc8b208e0a9e3293f774 a7a0add66b205967562c1fa9643b8421 22538214a3c917ff3b13a9e2035ca521 02f4701559fc40067e69bb426776a54f 5598baa59c716590d8841c6312d8349e Backward.dll…



#PyPI 上に悪意のあるパッケージが6つ見つかりました。背後にいる攻撃者は #W4SP の攻撃を模倣し、ユーザークレデンシャル、暗号ウォレット データなどを窃取していました。オープンソース エコシステムに台頭しつつある脅威の動向を解説します。 bit.ly/44CjShk

💣 Among others, @sekoia_io discovered yesterday 55 #PyPI malicious packages pushed by the same Threat actor. It's not the first time that we are seeing this actor pushing this kind of malicious packages. PyPI contacted and packages removed 👌 Related packages and IoCs below ↘️

I was annoyed of having to write README files for my projects. So I went ahead and created a CLI tool to auto-generate README files for any project regardless of programming language! 📜✨ It creates a comprehensive README based on your project. Check it out on #PyPI and #npm


🚨Over 22k packages are vulnerable (or over 120k by looser measurement) to a new #SoftwareSupplyChain attack vector: Hijacking abandoned #PyPI packages. Potentially critical for orgs relying on abandoned packages, learn more about our team's discovery: jfrog.co/4gpsbUH

#GitHub Token Accidental Leak Exposes the #Python Language, #PyPI and the Python Software Foundation (PSF) Repositories to Potential Attacks: 👇 thehackernews.com/2024/07/github…

Looking back at 2023 @mikefiedler discovered some impressive metrics that we want to share! @fastly #PyPI #pytho

⚠️🧵 RL researchers detected a new malicious campaign targeting #PyPI users. Several packages are pretending to be "time" related utilities, but are actually used to steal sensitive data like cloud tokens.


#Python: #PyPI temporarily shuts down new project creation and new user registration to mitigate an ongoing #malware upload campaign:

#PyPI A good blog post with analysis of #malicious #Python packages in PyPI by the @eset research team: #SoftwareSupplyChainSecurity 👇 welivesecurity.com/en/eset-resear…

#pyOneNote v0.0.1 is now on #PyPI pip install pyonenote It prints: 1⃣ header fields 2⃣ all metadata (i.e. all PropertySets such as jcidEmbeddedFileNode, jcidImageNode) 3⃣ embedded files and also dumps all embedded files github.com/DissectMalware… related



Let me introduce you to #pyOneNote v0.0.1; a pure python library to parse #one file format: github.com/DissectMalware… Covers 20 out of 38 FileNode types E.g.: .one in 835239c095e966bf6037f5755b0c4ed333a163f5cc19ba0bc50ea3c96e0f1628




Is it possible to encounter #malware on #PyPI? Learn how CloudGuard Spectralops.io - A Check Point Solution detected a malicious package on the leading #Python repository: bit.ly/3Zgo5V7

🔍Researchers have discovered a concerning surge in deceptive #npm and #PyPI packages distributed as part of a malicious campaign, aimed at extracting #Kubernetes configurations and #SSH keys. Read more👇 socradar.io/new-campaign-d… #cybersecurity #devops #supplychain #datatheft

How do you optimize package delivery for 950,000+ Python developers? Check out how we're using Individual Provider Anycast to power platforms like @PyPI, where small improvements × billions of requests = massive impact! fastly.com/blog/powering-… #fastforward #pypi

Something went wrong.
Something went wrong.
United States Trends
- 1. #เพียงเธอตอนจบ 1.14M posts
- 2. LINGORM ONLY YOU FINAL EP 1.12M posts
- 3. #FanCashDropPromotion 1,082 posts
- 4. Apple TV 8,688 posts
- 5. #FridayVibes 6,546 posts
- 6. Good Friday 58.6K posts
- 7. No Kings 208K posts
- 8. trisha paytas N/A
- 9. #FursuitFriday 12.9K posts
- 10. Mamdani 271K posts
- 11. Cuomo 117K posts
- 12. F1 TV 2,518 posts
- 13. Zendaya 3,335 posts
- 14. Shabbat Shalom 3,910 posts
- 15. #LastFourWatched N/A
- 16. Ayla 153K posts
- 17. Justice 327K posts
- 18. Happy Friyay 1,443 posts
- 19. New Yorkers 46.2K posts
- 20. My President 60.7K posts