|
|
|
|
|
by woodruffw
1217 days ago
|
|
I understand that this is meant to be an eye-popping press release (and implicitly a product spotlight), but some of these claims make me gag. It's not an attack "on" PyPI, or even an attack at all: someone is just spamming the index with packages. There's no evidence that these packages are being downloaded by anyone at all, or that the person in question has made any serious effort to conceal their attentions (it's all stuffed in the setup script without any obfuscation, as the post says). The executable in question isn't even served through PyPI (for reasons that are unclear to me): it's downloaded by the dropper script. Ironically, serving the binary directly would probably raise fewer red flags. Supply chain security is important; we should reserve phrases like "aggressive attack" for things that aren't script kiddie spam. |
|