Tag: PyPI

mrmustard 0.7.4 Malware: Credential Theft and Cleanup

mrmustard 0.7.4 was a malicious PyPI release that stole developer credentials and…

Brendan Smith

TrapDoor Hits npm, PyPI and Crates.io With AI Config Poisoning

TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets,…

Stephanie Adlam

Mini Shai-Hulud Hits TanStack npm Packages With Signed Malware

Mini Shai-Hulud abused trusted publishing to ship malicious TanStack npm packages with…

Stephanie Adlam

PyPI ZiChatBot Packages Linked to Suspected OceanLotus Campaign

Kaspersky reports a suspected OceanLotus campaign that used malicious PyPI packages to…

Stephanie Adlam

Python JSON Logger Vulnerability Exposes Millions of Users

The CVE-2025-27607 vulnerability was discovered in Python JSON Logger. Its exploitation required…

Stephanie Adlam

Aiocpa PyPI Package Targets Crypto Wallets

A malicious package named aiocpa was identified on the Python Package Index…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?