Python developers are becoming the target of this massive infostealing malware campaign

Cybersecurity researchers at Checkmarx have discovered a new infostealing campaign that used typosquatting and stolen GitHub accounts to distribute malicious Python packages to the PyPI repository.

In a blog post, Checkmarx’s Tal Folkman, Yehuda Gelb, Jossef Harush Kadouri and Tzachi Zornshtain said they discovered the campaign after a Python developer complained that he had fallen victim to the attack.