How 140k NuGet, NPM, and PyPi Packages Were Used to Spread Phishing Links??
An exciting joint research with our friends from @Checkmarx
https://t.co/hnHpbyHBsK
Joint research with @illustriaio reveals a phishing campaign involving over 140k packages on NuGet, NPM, and PyPi registries.
Attackers spam these ecosystems with packages containing links to retail websites with referral IDs to earn referral rewards
https://t.co/QlTJPOO0FG
PyTorch discloses malicious dependency chain compromise over holidays
"Since the PyPI index takes precedence, this malicious package was being installed instead of the version from our official repository״
If you installed PyTorch-nightly on Linux between Dec. 25 and Dec. 30, uninstall it and torchtriton immediately and use the latest nightly binaries.
Read the security advisory here: https://t.co/jnCSGXJRY0