Alerts
Events
DCR
Explore Cyware Products
Alerts
Events
DCR
Go to listing page
PyPI Feature Executes Code Automatically After Python Package Download
Malware and Vulnerabilities
September 02, 2022
The Hacker News
While threat actors have resorted to incorporating malicious code in the setup.py file, Checkmarx found that adversaries could achieve the same goals by running what's called a "pip download" command.
Read More
PyPI packages
Python Package Index (PyPI)
Supply Chain Attack
Code Execution Exploit
malicious code
Publisher
Previous
HelpSystems Acquires Outflank
Companies to Watch
Next
BumbleBee, a New Modular Backdoor Evolved From BookWorm
Malware and Vulnerabilities