Tech

Gmail servers hijacked by malicious PyPI packages to spread havoc – here’s how to stay safe

Share
Share


  • Socket found seven malicious packages on PyPI
  • The packages were abusing Gmail and WebSocket
  • They were removed from the platform

Several malicious PyPI packages were recently observed abusing Gmail to exfiltrate stolen sensitive data and communicate with their operators.

Cybersecurity researchers Socket, who found the packages, reported them to the Python repository and thus helped get them removed from the platform – however the damage has already been done.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable
Tech

Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable

MediaTek’s Kompanio Ultra makes a rare appearance, challenging the usual CPU suspects...

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy
Tech

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy

Most phishing incidents happen before new employees even understand how internal systems...

Analytical model evaluates performance of grant-free communication in densely populated IoT environment
Tech

Analytical model evaluates performance of grant-free communication in densely populated IoT environment

Credit: Pixabay/CC0 Public Domain Imagine a world where every smart device, from...