资讯

The past year has seen over 10,000 downloads of malicious packages hosted on the official Python package repository, ESET research finds.
The Python Package Index (PyPI) has introduced new protections against domain resurrection attacks that enable hijacking ...
To make mail hijacking more difficult, PyPI has been checking domain validity since June. In case of doubt, an abandoned email address loses its verification.
Over the weekend an attacker has been uploading thousands of malicious Python packages on the public PyPI (Python Package Index) software repository.
The method introduces another supply chain vulnerability for the future, as most security tools solely scan Python source code (PY) files, making them susceptible to missing such attacks. Zanki said ...
Devs unknowingly use “malicious” modules snuck into official Python repository Code packages available in PyPI contained modified installation scripts.
All-in-one Python project management tool written in Rust aims to replace pip, venv, and more. Here's a first look.