cognitive cybersecurity intelligence

News and Analysis

Search

Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

Cybersecurity researchers have discovered malicious libraries on the Python Package Index (PyPI) repository that aim to steal sensitive information. The packages bitcoinlibdbfix and bitcoinlib-dev pretend to be fixes for issues in a legitimate Python module called bitcoinlib, while the disgrasya package contains an automated carding script targeting WooCommerce stores. The counterfeit libraries managed to attract hundreds of downloads before removal. They replace a legitimate command with malicious code that attempts to extract sensitive database files.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts