23
New PondRAT Malware Hidden in Python Packages Targets Software Developers
(thehackernews.com)
Welcome to the Python community on the programming.dev Lemmy instance!
Past
November 2023
October 2023
July 2023
August 2023
September 2023
It's best to have a local copy of package repos with whitelisted libraries, or so I've heard. But containers are fine, too. Especially with VSCode .devcointainers, it's super easy to setup and distribute with the repo, there's really no reason not to do that.
The biggest issue here that a lot people don't realize is Bing AI, it's insanely easy to poison it's results, since it summarizes search results. It's only a matter of time before someone convinces it to start using or adding a typosquatted/malicious library to answers to a common programming question, and it will be a fun times ahead.