
Popular Python Library Vulnerability Exposes 43 Million Installations
Mar 10, 2025 · A recently disclosed vulnerability in the widely used Python JSON Logger library has exposed an estimated 43 million installations.
Malicious Python Packages on PyPI Downloaded 39,000+ Times, …
Apr 5, 2025 · Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI) repository that are designed to steal sensitive information and test stolen credit card data. "The malicious libraries both attempt a similar attack, overwriting the legitimate 'clw cli' command with ...
Python JSON Logger Vulnerability Allows Remote Code Execution …
5 days ago · A critical vulnerability in the widely-used python-json-logger library has been identified, potentially allowing attackers to execute arbitrary code.
Supply-chain attack analysis: Ultralytics - The Python Package …
Dec 11, 2024 · Last week, the Python project “ ultralytics ” suffered a supply-chain attack through a compromise of the projects’ GitHub Actions workflows and subsequently its PyPI API token. No security flaw in PyPI was used to execute this attack. Versions 8.3.41, 8.3.42, 8.3.45, and 8.3.46 were affected and have been removed from PyPI.
PyPI halted new users and projects while it fended off supply-chain attack
Mar 28, 2024 · PyPI, a vital repository for open source developers, temporarily halted new project creation and new user registration following an onslaught of package uploads that executed malicious code on...
Code injection in Python: examples and prevention - Snyk
Dec 6, 2023 · Code injection is a stealthy attack where malicious code is inserted into a software system, causing it to execute unintended commands. By exploiting vulnerabilities, an attacker can inject harmful code, leading to severe consequences, such as unauthorized data access, financial fraud, or total system takeover.
Major Python Infrastructure Breach – Over 170K Users …
Mar 25, 2024 · The Checkmarx Research team has unearthed a sophisticated attack campaign that leveraged fake Python infrastructure to target the software supply chain, affecting over 170,000 users, including the Top.gg GitHub organization and several individual developers.
When Python Is Poisoned | How Runtime Security Stops the tj-actions Attack
Mar 21, 2025 · Read SentinelOne's response to the tj-actions/changed-files attack and learn how to secure development pipelines with runtime security.
Malicious Python packages target popular Bitcoin library
Apr 3, 2025 · Popular Python crypto library targeted with a fake fix The Python packages we found both had names that target users of bitcoinlib, a popular Python library that contains features for creating and managing crypto wallets, interacting with the blockchain, and running Bitcoin scripts, among other things.
Over 170K users caught up in poisoned Python package ruse
Mar 25, 2024 · More than 170,000 users are said to have been affected by an attack using fake Python infrastructure with "successful exploitation of multiple victims."