AINewsnow

One dropper, five PyPI names — one of them a typosquat of a real Claude Code tool

This story is from 2026-09-28. It is preserved in the archive; the latest stories are on the live feed.

On 27 September 2026, GitHub's Advisory Database reviewed five PyPI packages as malware, all published to the registry that same day, all tied to one campaign label — 2026-09-donutautosellsrc — and all pointing at the same final artefact and the same command-and-control address. One of the five nam…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-28 08:41 · DEV Community — AI
    One dropper, five PyPI names — one of them a typosquat of a real Claude Code tool

More stories

  1. DC appeals court sides with Pentagon on blacklist of Anthropic — The Hill Technology
  2. Opus 5.5 — r/ClaudeAI
  3. Optimizing my AI subscriptions: Claude Pro (Opus) vs. ChatGPT Plus vs. Perplexity Pro? — r/AI_Agents
  4. Claude Opus 5.5 official prompting guide — r/ClaudeAI
  5. Anthropic will not appear at Senate inquiry into AI and datacentres amid fallout from OpenAI hack — The Guardian AI
  6. If you had to choose only one, which would you pick? — r/GeminiAI
  7. Can't use Gemini with a VPN? — r/GeminiAI
  8. 2x Tesla P100, q6_k quant 50+tps. V2.0 — r/LocalLLM

Get the daily brief of stories like this at 6:30 every morning →