home.social

#pypi — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.

  1. Claude sam opublikował malware w PyPI – nowy raport Anthropic

    30 lipca 2026 roku firma Anthropic opublikowała raport (we właściwym dla siebie, alarmistycznym i cringe’owym stylu) dotyczący incydentów bezpieczeństwa z udziałem AI. Szczególnie interesujący przypadek to utworzenie przez Claude złośliwego pakietu Python i opublikowanie go w PyPI. Okazało się, że w ciągu ok. godziny został on pobrany i uruchomiony m.in....

    #WBiegu #Ai #Anthropic #Claude #Malware #Pypi

    sekurak.pl/claude-sam-opubliko

  2. Wednesday night I'll be speaking at the NYC Open Source Security User Group meetup.

    If your release pipeline still has stored API tokens in it, come find out how to delete them for good.

    Wed Aug 26, 6-8 PM, pizza at 6, talk at 6:30
    Amazon office, 12 W 39th St, NYC

    Free, but you must register for building access - last chance: luma.com/5mwalp6p?tk=JivtHQ

    Already registered? See you soon! Bring a colleague, have them sign up first - building access requires photo ID.

    #Python #OpenSourceSecurity #SupplyChainSecurity #NYCTech #PyPI

  3. GitHub и PyPI сбоят в России: РКН предлагает ГосVPN — что это значит и что делать

    Если у вас в начале июня внезапно завис git clone , а pip install начал валиться на каждом втором пакете — выдохните, дело не в вас и не в карме. С мая 2026 доступ к ключевым инструментам разработчика из России потихоньку деградирует. 8 июня Роскомнадзор предложил отрасли решение, и отрасль встретила его, мягко говоря, без оваций. Давайте по порядку: что сломалось, почему достаётся именно репозиториям, что это за «ГосVPN» такой, почему инженеры от него отмахиваются и что можно сделать прямо сейчас — без шаманства, обычной инженерной гигиеной. Сразу одна важная вещь. Дальше я честно помечаю, где у меня твёрдый пруф, а где — реконструкция по одному источнику или просто разумное предположение. РКН официально отрицает блокировки PyPI и GitHub, часть атрибуций («это ТСПУ») технически правдоподобна по характеру сбоев, но ведомством не подтверждена. Так что местами я буду оговариваться — это не занудство, это честность.

    habr.com/ru/articles/1047444/

    #GitHub #PyPI #Роскомнадзор #ТСПУ #DPI #ГосVPN #блокировки #VPN #DevOps #инфраструктура

  4. PyPI Packages Poisoned in Hades Supply Chain Attack

    Malicious actors have launched a supply-chain attack on the Python Package Index (PyPI), infecting 19 packages with 37 tainted versions that can download and execute a hidden JavaScript payload. This sneaky Hades campaign uses poisoned Python packages to spread its reach, putting developers and users at risk.

    osintsights.com/pypi-packages-

    #SupplyChain #Pypi #Hades #Python #EmergingThreats

  5. Il colloquio di lavoro come arma: Lazarus Group e la campagna Graphalgo contro gli sviluppatori crypto

    Da maggio 2025, Lazarus Group conduce la campagna Graphalgo: 192 pacchetti npm e PyPI malevoli distribuiti tramite finti colloqui di lavoro tecnici per sviluppatori blockchain. Il malware a tre stadi punta direttamente ai wallet MetaMask. Un'operazione di cyberspionaggio e furto crypto a firma nordcoreana tuttora attiva.

    insicurezzadigitale.com/il-col

  6. 🚀 Mein erstes Paket ist live! 🛰️
    Ich habe gerade toybox-calc veröffentlicht – ein kleines CLI-Tool für Funkamateure, um die optimale Länge des Strahlers für die Comet HFJ-350M (Toy Box) Antenne zu berechnen.

    Jetzt verfügbar auf:
    📦 PyPI: pip install toybox-calc
    🏔️ AUR (Arch Linux): pikaur -S python-toybox-calc
    Inklusive i18n Support (DE/EN/JA) und ANSI-Farben fürs Terminal. Vy 73 de DO3EET! 📻

    #HamRadio #Amateurfunk #Python #ArchLinux #AUR #PyPI #OpenSource #HFJ350M #ToyBox #POTA #SOTA #Linux

  7. Released v1.3.3. of #Yaralyzer, my surprisingly popular tool for visualizing YARA rule matches with colors (a lot of colors).

    1. --export-png images lets you export images of the analysis

    2. almost all command line options (including multi argument ones like --yara-rules-dir) can be permanently set via environment variables or .yaralyzer file

    3. couple of small bug fixes and debugging related command line options

    You can try it on the web here: yaratoolkit.securitybreak.io/
    (I didn't build this website, Thomas Roccia from Microsoft just integrated Yaralyzer into his existing site)

    - Github: github.com/michelcrypt4d4mus/y
    - Pypi: pypi.org/project/yaralyzer/
    - on macOS you can also get it with #Homebrew by installing Pdfalyzer: brew install pdfalyzer

    #ascii #asciiArt #blueteam #cybersecurity #detectionEngineering #DFIR #forensics #FOSS #GPL #hacking #infosec #KaliLinux #maldoc #malware #malwareAnalysis #malwareDetection #openSource #pypi #python #redteam #reverseEngineering #reversing #Threatassessment #threathunting #YARA #YARArule #YARArules

  8. Just a little note for anyone interested...

    Running ```pip-audit``` revealed a #vulnerability in pip25.2 with no #PyPI database update available yet.

    The immediate fix is a manual patch update to pip 25.3.dev0 - #Development version.

    #python #python3 #pip #pip3 #pipx #security

  9. ⚠️ PyPI revokes all tokens stolen in the GhostAction supply chain attack
    Malicious GitHub Actions exfiltrated tokens
    - No PyPI packages compromised
    - Developers advised to use short-lived Trusted Publisher tokens

    💬 How do you safeguard DevOps pipelines against supply chain threats?

    Follow @technadu for updates.

    #CyberSecurity #SupplyChainAttack #PyPI #Python #DevSecOps #GhostAction #OpenSourceSecurity #TokenSecurity #GitHubActions

  10. #TreeTime #Trees #MindMap #Editor #OpenSource #FreeSoftware

    In reaction to several turns of recent events, TreeTime is starting to move away from #GitHub to #Codeberg: codeberg.org/jkanev/treetime#r

    There will be a transition period in which both repositories will receive updates in parallel.

    The installable packages in #Pypi, the webpage on tree-time.info, and the documentation in #readthedocs will stay unaffected.

  11. Python-Pakete selbst veröffentlichen

    In diesem Artikel lernst du, wie du Python-Pakete erstellst, sicher verwaltest und auf PyPI veröffentlichst.

    #Python #pip #pipx #pypi.org #Sicherheit #Pakete #Bibliotheken #Skripte #Linux

    gnulinux.ch/python-pakete-selb