Malicious Python packages are stealing vital data and have already been downloaded thousands of times


  • The researchers found three malicious PyPI packages, two led Bitcoin developers and a Woocommerce store
  • Two are designed to steal data, and the third to test valid credit cards
  • Since then, the three have been eliminated from the repository

It was discovered that multiple open source software packages in the repository of the python package index (PyPI) are malicious, probably compromising thousands of devices, experts warned.

ReversingLabs cybersecurity researchers found two malicious packages, “Bitcoinlibdbfix” and “Bitcoinlib-Dev”, which have about 2,000 downloads.

Leave a Comment

Your email address will not be published. Required fields are marked *