#pip #PyPi #Python #Setup #Foundation #Attack: “PyPI is the leading Python repository,. . .

Source: https://www.linkedin.com/feed/update/urn%3Ali%3Ashare%3A6963169326367461376

#pip #PyPi #Python #Setup #Foundation #Attack: PyPI is the leading Python repository, the most commonly in use by Python users. Every python developer is familiar with the ‘pip install’ daily routine to bring the Python software they need. 10 #malicious Python packages exposed in latest #repository #attack: #Supplychain #attacks are moving #GitHub toward digitally signed packages: #PyPi has 613,000 active users, and its #code is used in more than 390,000 projects. #Installing from #PyPi through the #pip command is a foundational step for starting or setting up many Python projects. PePy, a site that estimates Python project downloads, suggests most of the malicious packages saw #hundreds of #downloads.
https://lnkd.in/geAJ_RkP

IN-DEPTH: #Python #Repository #Malware: https://lnkd.in/gaSd9YX5

CloudGuard Spectral detects several malicious packages on PyPI – the #official #software #repository for #Python #developers
https://lnkd.in/g5a4THFC :

#ZeroTrust #OpenSource #Digital #Trust #Poisoned #GitHub #Install
Researchers have discovered yet another set of #malicious #packages in #PyPi, the #official and #most #popular #repository for #Python #programs and #code #libraries. Those #duped by the seemingly #familiar packages could be subject to #malware #downloads or #theft of #user #credentials and #passwords.

Such supply-chain attacks are becoming increasingly common, especially among #open #source #software #repositories that support a wide swath of the world’s #software. #Python’s repository is a frequent target, with researchers finding #malicious #packages in September 2017; June, July, and November 2021; and June of this year. But trick packages have also been found in #RubyGems in 2020, NPM in December 2021, and many more open source repositories.

Most notably, a private-source #supply-#chain #attack by Russian hackers through the #SolarWinds business software wreaked notable havoc, resulting in the infection of more than 100 companies and at least nine #US #federal #agencies, including the National Nuclear Security Administration (NNSA), the Internal Revenue Service, the U.S. Department of State, and the U.S. Department of Homeland Security.

Global Risk Management Network, LLC: Future of AI-Computer Science-Data Science-Finance Are All Here:

New York State: Join Dr. Yogi Malhotra to get up to speed on Cloud Technology.: Dr. Yogesh Malhotra AWS Partner, MIT-Princeton AI Faculty-SME:

YogeshMalhotra.com: We Create the Digital Future™. You Can Too! Let’s Show You How!
New York State: Join Dr. Yogi Malhotra to get up to speed on Cloud Technology.
USAF-AFRL Ventures: Global AI-ML-Quant-Cyber-Crypto-Quantum-Risk Computing Practices:
AIMLExchange™: AIMLExchange.com: We Create the Digital Future™
BRINT™: BRINT.com: From Future of Finance™ to Future of FinTech™
C4I-Cyber™: C4I-Cyber.com: Because the Future of the World Depends Upon It™

Share this post
Avatar photo

Global Post AI-Quantum Finance & Trading Networks Pioneer Dr.-Eng.-Prof. Yogesh Malhotra is the “Singular Post AI-Quantum Pioneer” identified by Grok AI with R&D impact recognized among Artificial Intelligence (AI) and Quantitative Finance Nobel Laureates. As MIT-Princeton AI-ML-Cyber-Crypto-Quantum Finance & Trading and FinTech-Crypto Faculty-Industry Expert, and U.S. and Global Hedge Funds Advisory & Venture Capital CEO-CTO Teams Mentor, he has pioneered Silicon Valley-Wall Street-Pentagon Digital CEO-CTO Practices, Technologies, and Networks from world’s first-foremost-largest Global Digital Transformation Networks to New York State IDEA Award recognized Pentagon-USAF MVP Global Post AI-Quantum Networks pioneering Future of Finance and Trading practices as Trillion-Dollar Wall Street Hedge Funds and Investment Banks leader.