#pypi — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #pypi, aggregated by home.social.
-
If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.
This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.
The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.
If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
Read more: https://github.com/astral-sh/setup-uv/releases/tag/v9.0.0 -
If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.
This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.
The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.
If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
Read more: https://github.com/astral-sh/setup-uv/releases/tag/v9.0.0 -
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Just released multipart-2.0.0 to #pypi.
This is a fast and robust #Python parser for multipart/form-data (HTTP form requests) supporting both non-blocking #ASGI and blocking #WSGI applications.
changelog: https://multipart.readthedocs.io/en/latest/changelog.html#release-2-0
pypi: https://pypi.org/project/multipart/
And when I say 'fast' I mean it: https://defnull.de/2026/python-multipart-benchmark/
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Today's the day! Come on out for story time and good ideas when I share details on the Anatomy of a Phishing Campaign I handled for #PyPI around this time last year.
https://ep2026.europython.eu/session/anatomy-of-a-phishing-campaign
#EuroPython2026 #EP2026 #Python #OpenSource #SupplyChain #Security
-
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.
Pulse ID: 6a5665a177561cba872b779e
Pulse Link: https://otx.alienvault.com/pulse/6a5665a177561cba872b779e
Pulse Author: AlienVault
Created: 2026-07-14 16:36:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault
-
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.
Pulse ID: 6a5665a177561cba872b779e
Pulse Link: https://otx.alienvault.com/pulse/6a5665a177561cba872b779e
Pulse Author: AlienVault
Created: 2026-07-14 16:36:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault
-
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.
Pulse ID: 6a5665a177561cba872b779e
Pulse Link: https://otx.alienvault.com/pulse/6a5665a177561cba872b779e
Pulse Author: AlienVault
Created: 2026-07-14 16:36:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault
-
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.
Pulse ID: 6a5665a177561cba872b779e
Pulse Link: https://otx.alienvault.com/pulse/6a5665a177561cba872b779e
Pulse Author: AlienVault
Created: 2026-07-14 16:36:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault
-
Compromised npm Packages in the AsyncAPI Namespace Deliver Miasma Botnet Loader
Four npm packages in the AsyncAPI namespace were compromised to distribute a multi-stage botnet loader called Miasma. The attack utilized trusted GitHub Actions publishing but originated from a poisoned source commit. Malicious code was injected into legitimate source files that execute when imported, launching a detached Node.js process to download an 8.25 MB encrypted payload from IPFS. The final payload is a sophisticated tasking framework supporting multiple command-and-control channels including REST, Nostr relays, IPFS, Ethereum smart contracts, and BitTorrent DHT. The framework establishes persistence via systemd services on Linux and fake NodeJS directories, supporting file operations, shell execution, data collection, and cross-ecosystem propagation capabilities for npm, PyPI, RubyGems, and Cargo ecosystems.
Pulse ID: 6a5665a177561cba872b779e
Pulse Link: https://otx.alienvault.com/pulse/6a5665a177561cba872b779e
Pulse Author: AlienVault
Created: 2026-07-14 16:36:49Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #GitHub #InfoSec #Linux #NPM #Nodejs #OTX #OpenThreatExchange #PyPI #RAT #RCE #Rust #bot #botnet #AlienVault
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Pulse ID: 6a546e33879dc2bce62e418f
Pulse Link: https://otx.alienvault.com/pulse/6a546e33879dc2bce62e418f
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Pulse ID: 6a546e33879dc2bce62e418f
Pulse Link: https://otx.alienvault.com/pulse/6a546e33879dc2bce62e418f
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Pulse ID: 6a546e33879dc2bce62e418f
Pulse Link: https://otx.alienvault.com/pulse/6a546e33879dc2bce62e418f
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Pulse ID: 6a546e33879dc2bce62e418f
Pulse Link: https://otx.alienvault.com/pulse/6a546e33879dc2bce62e418f
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Pulse ID: 6a546e33879dc2bce62e418f
Pulse Link: https://otx.alienvault.com/pulse/6a546e33879dc2bce62e418f
Pulse Author: Tr1sa111
Created: 2026-07-13 04:48:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #bot #Tr1sa111
-
rainlog 1.1.0
- New **Comparison** chart mode: press `m` in monthly or yearly grouping to see year-over-year bars side by side.
#Python #PyPI #Rain #Weather #OpenSource -
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
quicktipp #117: Bootstrapping a portable Python bundle on MS Windows using the `pywinbundle` tool.
https://github.com/christian-korneck/pywinbundle
A bundle is a bit like a venv, but self-contained and can get moved/renamed to any path or copied to any Windows machine. The bundle will continue to work, even if there is no existing Python installation.
-
Один комментарий на Хабре — и ещё один пакет для Django Admin
Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.
https://habr.com/ru/articles/1057784/
#Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps
-
Один комментарий на Хабре — и ещё один пакет для Django Admin
Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.
https://habr.com/ru/articles/1057784/
#Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps
-
Один комментарий на Хабре — и ещё один пакет для Django Admin
Недавно я опубликовал на Хабре статью о небольшом пакете django-scroll-to-top , который добавляет кнопку «Наверх» в проекты на Django. Сам пакет решает довольно локальную задачу, но обсуждение под статьёй оказалось интереснее, чем я ожидал. В комментариях возник вполне закономерный вопрос: насколько вообще подобным интерфейсным дополнениям место в стандартной Django Admin? Ведь каждое установленное приложение добавляет свои пункты в боковое меню, и со временем административная панель действительно может начать выглядеть перегруженной. Один из комментариев заставил меня посмотреть на эту проблему немного под другим углом. В результате вместо долгого спора появился ещё один небольшой open-source-пакет — теперь уже для сворачивания групп приложений в боковой панели Django Admin.
https://habr.com/ru/articles/1057784/
#Django #Django_Admin #Python #open_source #PyPI #UX #cookie #плагины_Django #административная_панель #django_admin_collapse_apps
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.
Pulse ID: 6a50a4bc4687b8b6b035b1a5
Pulse Link: https://otx.alienvault.com/pulse/6a50a4bc4687b8b6b035b1a5
Pulse Author: CyberHunter_NL
Created: 2026-07-10 07:52:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.
Pulse ID: 6a50a4bc4687b8b6b035b1a5
Pulse Link: https://otx.alienvault.com/pulse/6a50a4bc4687b8b6b035b1a5
Pulse Author: CyberHunter_NL
Created: 2026-07-10 07:52:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.
Pulse ID: 6a50a4bc4687b8b6b035b1a5
Pulse Link: https://otx.alienvault.com/pulse/6a50a4bc4687b8b6b035b1a5
Pulse Author: CyberHunter_NL
Created: 2026-07-10 07:52:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.
Pulse ID: 6a50a4bc4687b8b6b035b1a5
Pulse Link: https://otx.alienvault.com/pulse/6a50a4bc4687b8b6b035b1a5
Pulse Author: CyberHunter_NL
Created: 2026-07-10 07:52:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
A cluster of npm and PyPI packages typosquatting popular payment applications has been detected by Socket's AI scanner, which automatically blocks malicious packages in your code, as well as preventing them from being published.
Pulse ID: 6a50a4bc4687b8b6b035b1a5
Pulse Link: https://otx.alienvault.com/pulse/6a50a4bc4687b8b6b035b1a5
Pulse Author: CyberHunter_NL
Created: 2026-07-10 07:52:28Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #NPM #OTX #OpenThreatExchange #PyPI #TypoSquatting #bot #CyberHunter_NL
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.
Pulse ID: 6a4d89817cfad2c0f464e67a
Pulse Link: https://otx.alienvault.com/pulse/6a4d89817cfad2c0f464e67a
Pulse Author: AlienVault
Created: 2026-07-07 23:19:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #Edge #Endpoint #InfoSec #Malware #NPM #OTX #OpenThreatExchange #PyPI #RAT #bot #AlienVault
-
Coordinated npm and PyPI Campaign Typosquats Popular Secure Payment Apps
Socket's AI scanner identified 17 malicious packages across npm and PyPI ecosystems published simultaneously on July 7, 2026. The packages typosquatted legitimate PaySafe, Skrill, and Neteller payment SDK names to steal developer credentials and tokens. The malware implements sophisticated anti-analysis techniques including sandbox detection based on CPU cores and hostname patterns, multi-layer C2 domain obfuscation using XOR encoding, and selective activation gating. Upon execution, the packages exfiltrate environment variables containing API keys, secrets, tokens, and authentication credentials to AWS-hosted infrastructure via an ngrok endpoint. The campaign demonstrates coordinated cross-ecosystem capabilities, proper operational security through varied obfuscation keys, and knowledge of defender technologies, suggesting an organized threat actor with financial motivation.
Pulse ID: 6a4d89817cfad2c0f464e67a
Pulse Link: https://otx.alienvault.com/pulse/6a4d89817cfad2c0f464e67a
Pulse Author: AlienVault
Created: 2026-07-07 23:19:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #CyberSecurity #Edge #Endpoint #InfoSec #Malware #NPM #OTX #OpenThreatExchange #PyPI #RAT #bot #AlienVault