GeistHaus
log in · sign up

Lightning Got Owned: When `import lightning` Steals Your Credentials

pydevtools.com

Malicious lightning PyPI versions 2.6.2 and 2.6.3 shipped a daemon-thread payload that runs on import, steals credentials, and worms into npm.

0 pages link to this URL

No pages have linked to this URL yet.