Researchers discovered malicious packages on the Python Package Index (PyPi), which mimic legitimate DeepSeek packages and are loaded with infostealers to steal sensitive data. The packages were downloaded over 200 times before they were deleted. Experts warn that developers need to implement strong security practices, verify package sources, and use automated scanning tools to avoid similar cyber threats, as malicious actors are increasingly using AI to write harmful code and choosing popular platforms to maximise potential victims.
Hackers Hide Malware in Fake DeepSeek PyPI Packages
Cybersecurity researchers have identified a malware attack targeting the Python Package Index (PyPI), a repository for Python software. The attack, aimed at developers, machine learning