Capa Learning

Dr. Mercy I. Nwankwo is a Tech enthusiast with a passion for writing, blogging & coaching.

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

A recent discovery by cybersecurity researchers has revealed a malicious package in the Python Package Index (PyPI) repository. This package, named termncolor, utilizes a dependency called colorinal to execute malicious activities, including establishing persistence and achieving code execution. Zscaler ThreatLabz …

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks Read More »