Warning! Malicious PyPI Packages Stealing Cloud Tokens Downloaded Over 14,100 Times Before Removal
104/68 Monday, March 17, 2025 Cybersecurity researchers have uncovered a malicious campaign using fake packages in the Python Package Index (PyPI) to steal sensitive data, including cloud access tokens. According to ReversingLabs, 20 malicious packages were identified in two separate sets, collectively downloaded over 14,100 times before being removed from PyPI. The most downloaded malicious […]