Tech

Malicious Python packages are stealing vital data, and have been downloaded thousands of times already

Share
Share


  • Researchers found three malicious PyPI packages, two targeting bitcoin developers, and one WooCommerce stores
  • Two are designed to steal data, and the third to test for valid credit cards
  • All three have since been removed from the repository

Multiple open source software packages on the Python Package Index (PyPI) repository were found to be malicious, likely compromising thousands of devices, experts have warned.

Cybersecurity researchers at ReversingLabs found two malicious packages, “bitcoinlibdbfix” and “bitcoinlib-dev”, which cumulatively have around 2,000 downloads.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Amazon says it expects to cut human workers and replace them with AI
Tech

Amazon says it expects to cut human workers and replace them with AI

Amazon CEO Andy Jassy urges workers to be “curious about AI” It...

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions
Tech

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions

Leaked image shows a rounded square design and a large lens Hints...

Microsoft working on next-gen Xbox video game console
Tech

Microsoft working on next-gen Xbox video game console

Credit: CC0 Public Domain Xbox president Sarah Bond on Tuesday confirmed that...