#pypi


TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

May 25, 2026 // 19:10

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more […]

PyPI Packages Deliver ZiChatBot Malware via Zulip APIs on Windows and Linux

May 7, 2026 // 12:28

Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot […]

PyPI package with 1.1M monthly downloads hacked to push infostealer

Apr 27, 2026 // 19:57

An attacker pushed a malicious version of the popular elementary-data package Python Package Index (PyPI) to steal sensitive developer data and cryptocurrency wallets. The dangerous […]

Compromised Telnyx PyPI package: Malware concealed within WAV audio files.

Mar 28, 2026 // 00:37

TeamPCP hackers broke into the Telnyx package on the Python Package Index today. They uploaded harmful versions containing credential-stealing malware hidden in a WAV file. […]

Compromised LiteLLM Package Stole Credentials, Tokens from PyPI Users

Mar 25, 2026 // 10:57

The hacking group TeamPCP is continuing its supply chain attacks, now targeting the widely used “LiteLLM” Python package on PyPI and claiming to have obtained […]

Previous 1 … 3 4 5