Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks – The Hacker News
Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a dependency that allows it to establish persistence and achieve code…