The Python security team removed two trojanized Python libraries from PyPI (Python Package Index) that were stealing SSH and GPG keys from the projects of infected developers.
The Python security team removed two tainted Python libraries from PyPI (Python Package Index) that were found
Both libraries, “python3-
The name python3-
The expert discovered the two libraries on December 1, by the German software developer Lukas Martini.
“Just a quick heads-up: There is a fake version of this package called python3-
The “python3-dateutil” library was created and uploaded on PyPI on November 29, the “
The experts removed the two libraries the same day Martini reported his discovery to
The jeIlyfish library
The tainted library attempts to
Developers that used any of the two tainted libraries have to change all their SSH and GPG keys used since
[adrotate banner=”9″] | [adrotate banner=”12″] |
(
[adrotate banner=”5″]
[adrotate banner=”13″]