Hackers compromised 19 PyPI packages, including bioinformatics tools Dynamo and CoolBox, in the Shai-Hulud supply-chain attack. The malware uses a.pth file and obfuscated JavaScript to steal developer secrets, with execution triggered simply by starting Python. Socket discovered the campaign, which now totals 453 malicious artifacts.
Tap to vote and see what everyone thinks.
Microsoft packages hit by credential stealer again
Summary by ByteBrief