VMConnect: Malicious PyPI packages imitate popular open source modules

ReversingLabs has identified several malicious Python packages on the Python Package Index (PyPI) open source repository. In all, ReversingLabs researchers uncovered 24 malicious packages imitating three, popular open source Python tools: vConnector, a wrapper module for pyVmomi VMware vSphere bindings; as well as eth-tester, a collection of tools for testing ethereum based applications; and databases, a tool that gives asyncro support for a range of databases.

The post VMConnect: Malicious PyPI packages imitate popular open source modules appeared first on Security Boulevard.

03 August 2023


>>More