AWS keys stolen by malicious PyPI package with thousands of downloads




  • Researchers discover three-year old malicious package in PyPI
  • The package is a typosquatted version of Fabric, with 37,000 downloads
  • Its goal is to steal AWS login credentials from the developers

A malicious Python package has been hiding in the Python Package Index (PyPI) for years, stealthily stealing people’s Amazon Web Service (AWS) credentials.

Cybersecurity researchers Socket outlined how a package called “fabrice” was uploaded to the repository back in 2021 – before PyPl deployed its advanced scanning tool.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

Site Statistics
  • Today's visitors: 3
  • Today's page views: : 4
  • Total visitors : 372
  • Total page views: 433

Powered By WordPress | Joblook