One dropper, five PyPI names — one of them a typosquat of a real Claude Code tool
This story is from 2026-09-28. It is preserved in the archive; the latest stories are on the live feed.
On 27 September 2026, GitHub's Advisory Database reviewed five PyPI packages as malware, all published to the registry that same day, all tied to one campaign label — 2026-09-donutautosellsrc — and all pointing at the same final artefact and the same command-and-control address. One of the five nam…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-28 08:41 · DEV Community — AI
One dropper, five PyPI names — one of them a typosquat of a real Claude Code tool