The malicious package that never showed up in anyone's requirements.txt
This story is from 2026-09-09. It is preserved in the archive; the latest stories are on the live feed.
On 3 September 2026, GitHub's Advisory Database published two malware reports for PyPI packages, credited to OpenSSF's malicious-packages tracking effort. Read separately, they look like routine entries in a database that logs thousands of these a year. Read together, they describe a specific trick…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-09 17:27 · DEV Community — AI
The malicious package that never showed up in anyone's requirements.txt