PyPI package 'ctx' and PHP library 'phpass' hijacked to obtain AWS keys

clock • 3 min read
PyPI package 'ctx' and PHP library 'phpass' hijacked to obtain AWS keys
Image:

PyPI package 'ctx' and PHP library 'phpass' hijacked to obtain AWS keys

Both attacks appears to be the work of the same actor

Security researchers this week identified two corrupt Python and PHP packages in what appears to be yet another instance of a software supply chain attack targeting the open-source ecosystem. Py...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now

 

Already a Computing member?

Login

You may also like
California AI Safety Bill sparks uproar in Silicon Valley

Artificial Intelligence

It would require AI companies to create a 'kill switch' to disable powerful AI models in case of emergencies

clock 10 June 2024 • 3 min read
London hospitals in disarray as cyberattack cripples testing services

Hacking

Poses serious challenge to urgent and emergency care

clock 05 June 2024 • 4 min read
Mistral unveils AI code-generation model Codestral

Artificial Intelligence

The model has already undergone testing by JetBrains, SourceGraph, LlamaIndex and others

clock 31 May 2024 • 2 min read

More on Threats and Risks

Threat group 'systematically compromising Snowflake customer instances'

Threat group 'systematically compromising Snowflake customer instances'

165 organisations notified to date

Kyle Alspach
clock 11 June 2024 • 2 min read
Microsoft warns of potential Azure Service Tags misuse by hackers

Microsoft warns of potential Azure Service Tags misuse by hackers

Ten specific Azure services are currently identified as susceptible

clock 11 June 2024 • 2 min read
Microsoft overhauls Recall, makes it opt-in

Microsoft overhauls Recall, makes it opt-in

The move comes after security concerns from experts

clock 10 June 2024 • 3 min read