#PyPISecurity
donutautosellsrc PyPI package (v0.3.7 – 0.3.9) is CRITICAL: contains obfuscated infostealer using blockchain C2. Uninstall affected versions now and monitor for data loss. https://radar.offseq.com/threat/malicious-code-in-donutautosellsrc-pypi-adf2fee072c2c5b1 #OffSeq #PyPISecurity #Malware
Malicious code in donutautosellsrc (PyPI)
During installation, the donutautosellsrc package fetches code hidden within an image containing a Python application with a native extension module. This native module is obfuscated and functions as an infostealer, collecting sensitive inf
radar.offseq.com
September 27, 2026 at 12:00 PM
CRITICAL: requests-cache-utils v1.0.0 (PyPI) contains install-time malware, exfiltrating browser data. Remove and avoid use. Full details: https://radar.offseq.com/threat/malicious-code-in-requests-cache-utils-pypi-e8c3f4806b2131ca #OffSeq #Malware #PyPISecurity
Malicious code in requests-cache-utils (PyPI)
The requests-cache-utils PyPI package version 1.0.0 is a malicious package that overrides the setup.py install command to execute code during installation. This code downloads and executes a remote infostealer malware that targets browser d
radar.offseq.com
September 27, 2026 at 1:30 PM
Malicious code found in popular VSCode extensions & a PyPI package; millions affected. #VSCodeSecurity #PyPISecurity #OpenSourceSecurity
VSCode Extensions and PyPI Package Security Risks
Malicious code found in popular VSCode extensions & a PyPI package; millions affected. #VSCodeSecurity #PyPISecurity #OpenSourceSecurity
gbhackers.com
March 1, 2025 at 1:42 AM
AIMindUpdate News!
Are your Python packages safe? Info-stealers are lurking in PyPI! Learn how to defend against these threats and protect your code.#PyPISecurity #PythonMalware #InfoStealer

Click here↓↓↓
aimindupdate.com/2025/06/20/p...
PyPI Security: Info-Stealer Malware in Python Packages
Rising info-stealer threats in Python's PyPI. Learn how these attacks work & how to protect your code.
aimindupdate.com
June 22, 2025 at 5:30 AM
A key discussion point: how will Anthropic's donation bolster Python's security? Many hope it directly addresses long-standing vulnerabilities and infrastructure issues within PyPI, enhancing trust for developers. #PyPIsecurity 3/6
January 14, 2026 at 11:00 AM