T1059.006 8
- PyPI Package Impersonates SymPy to Deliver Cryptomining Malware
- Surveillance Malware Hidden in npm and PyPI Packages Targets Developers with Keyloggers, Webcam Capture, and Credential Theft
- Monkey-Patched PyPI Packages Use Transitive Dependencies to Steal Solana Private Keys
- The Bad Seeds: Malicious npm and PyPI Packages Pose as Developer Tools to Steal Wallet Credentials
- Malicious PyPI Package Exploits Deezer API for Coordinated Music Piracy
- North Korean APT Lazarus Targets Developers with Malicious npm Package
- Noxia: Emerging Dark Web Hosting Provider Targets Python, Node.js, Go, and Rust Ecosystems
- Typosquatting on PyPI: Malicious Package Mimics Popular 'browser-cookie3' Library to Steal Sensitive Data