Python Q&A site StackExchange hijacked to spread malware posing as answers

Researchers at Checkmarx have discovered a sophisticated campaign in which attackers built credibility within the Python Package Index (PyPI) community to spread crypto-draining, data-stealing malware.

Over a month ago, the attackers uploaded a number of non-malicious Python packages, such as ‘spl-types’, via the StackExchange Q&A website to build credibility and evade detection for a future attack.