#pip #PyPi #Python #Setup #Foundation #Attack: “PyPI is the leading Python repository,. . .

Source: https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A6963169326367461376

#pip #PyPi #Python #Setup #Foundation #Attack: PyPI is the leading Python repository, the most commonly in use by Python users. Every python developer is familiar with the ‘pip install’ daily routine to bring the Python software they need. 10 #malicious Python packages exposed in latest #repository #attack: #Supplychain #attacks are moving #GitHub toward digitally signed packages: #PyPi has 613,000 active users, and its #code is used in more than 390,000 projects. #Installing from #PyPi through the #pip command is a foundational step for starting or setting up many Python projects. PePy, a site that estimates Python project downloads, suggests most of the malicious packages saw #hundreds of #downloads.
https://lnkd.in/geAJ_RkP

IN-DEPTH: #Python #Repository #Malware: https://lnkd.in/gaSd9YX5

CloudGuard Spectral detects several malicious packages on PyPI – the #official #software #repository for #Python #developers
https://lnkd.in/g5a4THFC :

#ZeroTrust #OpenSource #Digital #Trust #Poisoned #GitHub #Install
Researchers have discovered yet another set of #malicious #packages in #PyPi, the #official and #most #popular #repository for #Python #programs and #code #libraries. Those #duped by the seemingly #familiar packages could be subject to #malware #downloads or #theft of #user #credentials and #passwords.

Such supply-chain attacks are becoming increasingly common, especially among #open #source #software #repositories that support a wide swath of the world’s #software. #Python’s repository is a frequent target, with researchers finding #malicious #packages in September 2017; June, July, and November 2021; and June of this year. But trick packages have also been found in #RubyGems in 2020, NPM in December 2021, and many more open source repositories.

Most notably, a private-source #supply-#chain #attack by Russian hackers through the #SolarWinds business software wreaked notable havoc, resulting in the infection of more than 100 companies and at least nine #US #federal #agencies, including the National Nuclear Security Administration (NNSA), the Internal Revenue Service, the U.S. Department of State, and the U.S. Department of Homeland Security.

Global Risk Management Network, LLC: Future of AI-Computer Science-Data Science-Finance Are All Here:

New York State: Join Dr. Yogi Malhotra to get up to speed on Cloud Technology.: Dr. Yogesh Malhotra AWS Partner, MIT-Princeton AI Faculty-SME:

YogeshMalhotra.com: We Create the Digital Future™. You Can Too! Let’s Show You How!
New York State: Join Dr. Yogi Malhotra to get up to speed on Cloud Technology.
USAF-AFRL Ventures: Global AI-ML-Quant-Cyber-Crypto-Quantum-Risk Computing Practices:
AIMLExchange™: AIMLExchange.com: We Create the Digital Future™
BRINT™: BRINT.com: From Future of Finance™ to Future of FinTech™
C4I-Cyber™: C4I-Cyber.com: Because the Future of the World Depends Upon It™

Supply-chain attacks are moving GitHub toward digitally signed packages.
Share this post
Avatar photo

Silicon Valley's 'Next Big Thing': "Do Something Epic: Save the World™": "Venture capitalist Roger McNamee recently implored Silicon Valley to embrace human-driven social networks that empower rather than exploit users as the Next Big Thing. Having pioneered such networks, we were invited to guide Silicon Valley three decades or so ago on building Digital enterprises for the Wild Wild Web*. Today, we are ready to again lead Silicon Valley to further advance human-driven technologies in collaboration with the AFRL..." - Dr. Yogesh Malhotra, Founder, AWS-Quantum Valley™: BRINT.com Know-Build-Monetize™ Networks: YM-ABC™: YogeshMalhotra.com: AIMLExchange.com : BRINT.com : C4I-Cyber.com