Security researchers discovered a malware campaign targeting Python Package Index (PyPI) users, involving malicious packages disguised as time utilities. These packages, such as “time-utils” and “execution-time-async,” steal sensitive data like cloud tokens. They use advanced exfiltration methods, encrypting data and transmitting it via blockchain to evade detection. Developers are urged to verify package sources and audit their environments.

Phishing Campaign Impersonates Booking.com, Plants Malware
Cybersecurity professionals have raised concerns over a new phishing campaign that imitates Booking.com to plant credential-stealing malware. The threat, first detected in December 2024, targets