Tech

Malicious Python packages are stealing vital data, and have been downloaded thousands of times already

Share
Share


  • Researchers found three malicious PyPI packages, two targeting bitcoin developers, and one WooCommerce stores
  • Two are designed to steal data, and the third to test for valid credit cards
  • All three have since been removed from the repository

Multiple open source software packages on the Python Package Index (PyPI) repository were found to be malicious, likely compromising thousands of devices, experts have warned.

Cybersecurity researchers at ReversingLabs found two malicious packages, “bitcoinlibdbfix” and “bitcoinlib-dev”, which cumulatively have around 2,000 downloads.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Warning: check your PC’s Windows 11 encryption feature to make sure your data is not at risk
Tech

Warning: check your PC’s Windows 11 encryption feature to make sure your data is not at risk

Concerns have been raised around the default drive encryption applied with Windows...

Robotics researchers develop algorithms that make mobile navigation more efficient
Tech

Robotics researchers develop algorithms that make mobile navigation more efficient

Zihao Dong, a Northeastern doctorate student, tested the algorithm on Northeastern’s Agile...

Air circulator vs fan: what’s the difference, and which one should you buy?
Tech

Air circulator vs fan: what’s the difference, and which one should you buy?

In this article we’re going to explore the difference between a fan...

A shockingly high amount of Microsoft code is now written by AI, CEO Satya Nadella admits
Tech

A shockingly high amount of Microsoft code is now written by AI, CEO Satya Nadella admits

Microsoft CEO Satya Nadella believes around a third of the company’s code...