News

Devs unknowingly use “malicious” modules snuck into official Python repository Code packages available in PyPI contained modified installation scripts.
PyPI package 'ctx' and PHP library 'phpass' hijacked to obtain AWS keys. ... Python Package Index (PyPI) module 'ctx' is one of the packages in question, with over 20,000 downloads each week.