In the PyPI attack, a malicious pull request exploited a script-injection flaw in a GitHub Actions workflow to add base64-encoded infostealer code to release 0.23.3, also affecting the project's ...
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact.
News briefs for July 17, 2019. Malicious Python libraries have been found on the official Python Package Index (PyPI), which contain a hidden backdoor that would activate when installed on Linux ...