In a stark reminder of the vulnerabilities inherent in open-source ecosystems, new revelations confirm that attackers are targeting Python Package Index (PyPI) repositories with sophisticated, multi-stage malware.
Security firm JFrog recently identified and reported a malicious package, “chimera-sandbox-extensions,” uploaded by the user “chimerai.”
Unlike...