Gmail servers kidnapped by malicious pypi packages to spread ravages – here we show you how to stay safe




  • Socket found seven malicious packages in Pypi
  • The packages were abusing Gmail and Websocket
  • They were removed from the platform

Recently several malicious Pypi packages were observed abusing Gmail to exfiltrate sensitive data to stolen and communicate with their operators.

Cybersecurity researchers Socket, who found the packages, informed them to the Python repository and, therefore, helped eliminate them from the platform, however, the damage has already been done.

Leave a Comment

Your email address will not be published. Required fields are marked *