#pypi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.
-
Восемь аниме-плееров рунета изнутри: шифр Цезаря, пустой параметр и домен, который увели
Я взял за основу популярную опенсорсную библиотеку парсеров аниме-плееров, запустил её — и получил от Kodik 500 Internal Server Error . Не «токен протух», не «IP заблокирован», а именно 500 на каждый запрос. Разбор занял вечер, а причина оказалась в одном символе: библиотека отправляла параметр ref пустым, а сервер требует его заполненным и раскодированным . Дальше выяснилось, что это не единичная поломка, а норма жанра. Один плеер полгода назад переехал на другой формат страницы. Другой отвечает бесконечным редиректом на самого себя. У третьего домен просто увели — сейчас там индонезийский интернет-магазин, а не аниме. Четвёртый прячет ссылки в WebSocket из обфусцированного бандла на 600 КБ, и его я честно не осилил. Под катом — разбор восьми плееров: как каждый отдаёт видео, где именно ломаются существующие парсеры и что из этого следует, если вы пишете что-то похожее. Библиотека получилась побочным продуктом и лежит в открытом доступе.
https://habr.com/ru/articles/1079156/
#python #парсинг #реверсинжиниринг #hls #m3u8 #аниме #pypi #github_actions #websocket
-
PyPI Packages Poisoned in Hades Supply Chain Attack
Malicious actors have launched a supply-chain attack on the Python Package Index (PyPI), infecting 19 packages with 37 tainted versions that can download and execute a hidden JavaScript payload. This sneaky Hades campaign uses poisoned Python packages to spread its reach, putting developers and users at risk.
-
Latest PyPi Compromise
A supply chain attack targeting the Microsoft DurableTask Python client compromised versions 1.4.1, 1.4.2, and 1.4.3 on PyPi. The threat actor gained access through a compromised GitHub account previously linked to attacks, using stolen credentials to dump GitHub secrets containing PyPi tokens. The evolved payload targets Linux systems, stealing credentials from AWS, Azure, GCP, Kubernetes, Vault, and password managers like Bitwarden and 1Password. It propagates via AWS SSM and Kubernetes lateral movement, limited to 5 targets per infected host. The payload scrapes shell history, bruteforces password managers, and establishes persistence through infection markers. Compromised packages were quarantined following analysis.
Pulse ID: 6a0ce3b0ad791179648c47b0
Pulse Link: https://otx.alienvault.com/pulse/6a0ce3b0ad791179648c47b0
Pulse Author: AlienVault
Created: 2026-05-19 22:26:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #BruteForce #CyberSecurity #GitHub #InfoSec #Linux #Microsoft #OTX #OpenThreatExchange #Password #PyPI #Python #RCE #SupplyChain #Word #bot #AlienVault
-
I have just published shaclgen 3.0.0b1, please test: 💾 https://pypi.org/project/shaclgen/3.0.0b1/
There was no release of #shaclgen since almost 5 years. There were many changes in between including major #rdflib releases. A changelog can be retrieved from the commit history.
-
One question about #PyPy #PyPi is how many functions like #xz will they NOT find at this point of minimal #Python library backdoors especially iF this is being used in the Enterprise #Fortune1000 and below as a vector IN, eh?
🐛🚪🚪🚪🚪🚪🚪🚪🚪🚪 🔍👀
☣️
👇
https://www.virustotal.com/graph/embed/ga60e68b3e1744e36b0e4b0cc98f17f1a19ec96449bb34313a0b3a4b3cf287cc3