More Typo-Squatting Malware Found on PyPI
Want to learn more about the latest malware attack that could be affecting your Python Packaging Index? Click here to check it out!
Join the DZone community and get the full member experience.
Join For FreeMalware was recently discovered on the Python Packaging Index that targets Windows users. The package was called colourama. If it had been installed, it would end up installing malware on your PC. It is basically hoping that you will misspell the popular colorama package.
You can read more about the malware on Medium where it describes malware as being a “Cryptocurrency Clipboard Hijacker."
I actually wrote about this issue last year when the Slovak National Security Office identified several malicious libraries on the Python Packaging Index.
I noticed this week that the Python Software Foundation is looking at adding security to PyPI in 2019, which they announced on their blog. Although, right now, it does not appear to say what kind of security will be added.
Stay tuned!
Published at DZone with permission of Mike Driscoll, DZone MVB. See the original article here.
Opinions expressed by DZone contributors are their own.
Comments