TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

PyPI Suspends New User and Project Creation in Wake of Malware Campaign

16 pointsby louislangabout 1 year ago

4 comments

sega_saiabout 1 year ago
It is scary. Here they caught the culprit quickly, but if they&#x27;ve been careful, I think they would be able to stay under the radar and still infect a fair few systems.<p>As a person who regularly runs pip install on my main desktop, I am definitely worried about arbitrary code execution that happens when you pip install. Sure I can run everything inside the container, but given that I do most of my work in python, I think that is too restrictive...
评论 #39857074 未加载
jvanderbotabout 1 year ago
Honest question: Is this unique to python? or can we expect this in Go, Rust, vcpkg, conan, etc?
评论 #39856865 未加载
richijabout 1 year ago
This one gained more traction: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39856756">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39856756</a>
nathantsabout 1 year ago
run littlesnitch or something similar to notice and prevent egress attempts. for now it seems the only effective defense.<p>hopefully somebody builds a disk snitch. would love to buy that.