PyPI repository flooded with 1,200+ dependency confusion packages imitating well-known companies and #opensource Python projects 🐍.
Reported to PyPI by @sonatype and removed within an hour 👏👏👏
https://t.co/vkKiAEVOSW
Scoop: Developer of popular 'colors' and 'faker' #opensource NPM projects has intentionally corrupted them—breaking THOUSANDS of projects that depend on them.
Done in retaliation against mega-corporations exploiting open source but not giving back:
https://t.co/YMskgBkmbo
👀 While performing large-scale static analysis of PyPI packages, @drownedcoast caught 3 malicious packages that target Windows & Linux machines, download #malware, and exfiltrate files related to Apache Mesos files.
https://t.co/oJ8fMOb6Cb
#OpenSource
By doing text analysis on PyPI packages I identified 3 malicious packages, including one targeting @ApacheMesos that has been downloaded 10k times!
https://t.co/9IPxzwJ8UE @pypi
My name is Marcus Flowers. I’m a U.S. Army Veteran, Democrat, and I believe in service.
At 18 years old, I swore an oath to defend the Constitution. That's why I’m running to unseat Marjorie Taylor Greene.
I have 255k followers. Can you give me a follow and join our campaign?
🐍 Ochrona by @drownedcoast
CLI tool for detecting vulnerabilities in Python dependencies and doing safe package installs
Has its own vuln DB, using data from:
* NIST NVD
* Github Advisory Database
* Vendor disclosures & blog posts
* PyPA Advisory DB
https://t.co/DFX7Hgkw9x
Want to make sure you’re only using dependencies with commercial-friendly licensing?
“license_type IN MIT,ISC,Apache-2.0…”
Want to make sure you’re not using dependencies that are no longer maintained?
“latest_update > NOW-90”
As of v1.1.0, Ochrona now has support for generic policy definitions. This means you can now add additional contextual metadata checks to your Python dependency usage beyond vulnerable package usage. Oh, and you can express them in plain English. #python#CyberSecurity