Two New Typosquatting Libraries Found on PyPI
Two new malicious packages were found on the Python Packaging Index (PyPI) that were designed to steal GPG and SSH keys according to ZDNet. The packages were named python3-dateutil and jeIlyfish where the first “L” is actually an I. These two libraries mimicked the dateutil and jellyfish packages respectively. The fake python3-dateutil would import the […]
Two New Typosquatting Libraries Found on PyPI Read More »
