There’s another malicious PyPl package – this one stealing data from developers

>

Investigators have discovered that criminals are impersonating a well-known cybersecurity company in an attempt to steal data from software developers.

Researchers at ReversingLabs recently discovered a malicious Python (opens in new tab) package on PyPI called “SentinelOne”. Named after a well-known United States cybersecurity firm, the package masquerades as a legitimate SDK client that allows easy access to the SentinelOne API from a separate project.