Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks
Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks 2025-08-18 at 15:02 By Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a dependency that allows it to establish persistence and achieve code execution. The package, named termncolor, realizes its nefarious functionality […]
React to this headline: