TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Malicious 'Checker' Packages on PyPI Probe TikTok and Instagram for Valid

3 pointsby feross3 days ago

1 comment

duskwuff2 days ago
Calling libraries &quot;malicious&quot; and &quot;malware&quot; simply because they interact with web service APIs in an unauthorized way, or because they could potentially be used for nefarious purposes, is a pretty serious overstatement.<p>Would I use these libraries in an application I was writing? Probably not. But I don&#x27;t see any evidence of <i>malice</i> here, like exfiltrating the usernames&#x2F;passwords to a third party or executing code from an unexpected source. At best, these libraries are <i>potentially unwanted</i>, not <i>malicious</i>.