Malicious Python packages dump your AWS secrets online



Multiple malicious Python packages leaking sensitive user information have been uncovered by security experts.

In a blog post (opens in new tab), Sonatype security researcher Ax Sharma says the packages: loglib-modules, pyg-modules, pygrata, pygrata-utils, and hkg-sol-utils, were exfiltrating people’s secrets, such as AWS credentials and environment variables, and uploading them to a publicly exposed endpoint (opens in new tab).



Source link

Previous articleRIP, Lightning cable: You showed what USB-C should have been
Next articleApple’s Upcoming M2 Pro Chip for High-End MacBook Pro and Mac Mini Will Reportedly Be 3nm