Author Topic: Python libraries caught stealing SSH and GPG keys  (Read 2037 times)

littleman

  • Administrator
  • Hero Member
  • *****
  • Posts: 6552
    • View Profile
Python libraries caught stealing SSH and GPG keys
« on: December 05, 2019, 07:01:17 PM »
Any Python people here?

https://www.zdnet.com/article/two-malicious-python-libraries-removed-from-pypi/

python3-dateutil

jeIlyfish

Quote
The two malicious clones were discovered on Sunday, December 1, by German software developer Lukas Martini. Both libraries were removed on the same day after Martini notified dateutil developers and the PyPI security team.

While the python3-dateutil was created and uploaded on PyPI two days before, on November 29, the jeIlyfish library had been available for nearly a year, since December 11, 2018.

rcjordan

  • I'm consulting the authorities on the subject
  • Global Moderator
  • Hero Member
  • *****
  • Posts: 16342
  • Debbie says...
    • View Profile
Re: Python libraries caught stealing SSH and GPG keys
« Reply #1 on: December 05, 2019, 11:48:07 PM »
Machine-raiding Python libraries squashed by community – Naked Security
https://nakedsecurity.sophos.com/2019/12/05/machine-raiding-python-libraries-squashed-by-community/