Security researchers at Socket have uncovered a malicious Python package that exploits developer trust and system integration to compromise Windows environments.
The malicious package, named psslib, is a typosquatting attack targeting the legitimate and widely used passlib library, resulting in immediate system shutdowns when users enter incorrect...
In a sophisticated new supply chain attack, threat actors have leveraged both Python’s PyPI and JavaScript’s NPM ecosystems to target developers and administrators on Windows and Linux platforms.
Discovered by researcher Ariel Harush, this campaign deploys typo-squatting and cross ecosystem name confusion techniques that...