cognitive cybersecurity intelligence

News and Analysis

Search

Malicious PyPI Package Targets Developer Credentials

Malicious PyPI Package Targets Developer Credentials

JFrog researchers have uncovered a multi-stage malware embedded in a Python package named chimera-sandbox-extensions. The malware steals sensitive data from corporate cloud environments. A user named chimerai uploaded the malicious package targeting developers using the Chimera sandbox platform. The Python Package Index (PyPI) removed the package after JFrog reported it. This incident exemplifies the evolving risks in the open-source software supply chain.

Source: www.bankinfosecurity.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts