2025‘s Thoughts
✦ April
When PyPI Becomes the Attack Vector: 39,000+ Downloads of Malicious Python Packages
Three Python packages made it onto PyPI, stole data, validated stolen credit cards, and were downloaded over 39,000 times. Here’s how they worked and what we can learn from it.