cognitive cybersecurity intelligence

News and Analysis

Search

New Campaign Attacking PyPI Users to Steal Sensitive Data Including Cloud Tokens

Security researchers discovered a malware campaign targeting Python Package Index (PyPI) users, involving malicious packages disguised as time utilities. These packages, such as “time-utils” and “execution-time-async,” steal sensitive data like cloud tokens. They use advanced exfiltration methods, encrypting data and transmitting it via blockchain to evade detection. Developers are urged to verify package sources and audit their environments.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts