• Daily Illinois
  • About
  • Contact
  • Privacy
  • Terms
  • DMCA
  • Sitemap
  • Write For Us
Daily illinois - USA | News, Sports & Updates Web Magazine
  • News
    • All
    • Business
    • Education
    • Politics
    • Sports
    • World
    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Lifesaving Domestic Violence Resources in Pinellas County

    Lifesaving Domestic Violence Resources in Pinellas County

    Non-Cash Compensations to Keep Employees Motivated!

    4 Powerful Non-Cash Compensations to Keep Employees Motivated!

    Brand Awareness Measurement Strategies

    8 Proven Brand Awareness Measurement Strategies to Grow

    Eco-Friendly Bubble Mailers: Boost Green Brand Reputation

    Eco-Friendly Bubble Mailers: Elevate Your Green Brand Reputation

    Unlock Faster App Development with Automation Testing

    Unlock Automation Testing to Master Faster App Development

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Highlights of AFC Asian Cup Qatar

    Highlights of AFC Asian Cup Qatar 2023

    Illinois sets a new record for cannabis sales. Doctors notice an increase in psychotic disorders due to the use of cannabis

    Illinois Sets a New Record for Cannabis Sales. Doctors Notice an Increase in Psychotic Disorders Due to the Use of Cannabis

  • Science & Tech
    • All
    • Ai - Artificial Intelligence
    • Apps
    • Mobile
    Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

    Having trouble with AirDrop? Discover ways to resolve the issue.

    MiniTool ShadowMaker Best Backup Software for Your Data

    MiniTool ShadowMaker Best Backup Software for Your Data

    What exactly is a Snapchat Streak

    What exactly is a Snapchat Streak?

    Access WhatsApp on your iPad through WhatsApp Web.

    Ways to Access WhatsApp on an iPad

    AI and Machine Learning Trends Revolutionizing Security

    7 AI and Machine Learning Trends Revolutionizing Security

    How-to-Lock-Your-Facebook-Profile-on-iPhone,-Android-&-Desktop

    How to Lock Your Facebook Profile on iPhone, Android & Desktop

    How to Log out of Facebook

    Steps to Sign Out of Facebook

    How to Know If Someone Blocked You on Snapchat

    How to Know If Someone Blocked You on Snapchat

    How to Update Apps on iPhone (2024 Guide)

    How to Update Apps on iPhone

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Castle

    10 Awesome Projects to Create in Minecraft

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft.png

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    How Immersive Gaming & VR are Shaping PC Gaming's Future

    How Immersive Gaming & VR are Shaping PC Gaming’s Future

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Dance Studios in to Get Cheap Dance Classes in Chicago

    9 Dance Studios in to Get Cheap Dance Classes in Chicago

    Video Game

    Video Game Workers Must Continue to Join Unions in 2024

    Exploring the Free Best Websites Online Games

    Exploring the Free Best Websites Online Games

    • F95zone
  • Lifestyle
    • All
    • Fashion
    • Food
    • Travel
    Top Caption Selfie Hacks to Boost Your Engagement Fast!

    10 Best Caption Selfie Hacks to Boost Your Engagement Fast!

    Understanding Ear Wax Build-Up With Causes & Solutions

    Top 5 Ways to Prevent Ear Wax Build-Up Naturally

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To.jpg

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To

    Tips for Choosing Furniture: Creating a Space that Reflects You

    Tips for Choosing Furniture: Creating a Space that Reflects You

    5 Ways Pool Liners Boost Energy Efficiency

    Save Money: 5 Ways Pool Liners Boost Energy Efficiency

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Fat Reduction Treatments to Sculpt Your Dream Body!

    2 Best Fat Reduction Treatments to Sculpt Your Dream Body!

    Proven Steps to Get Rid of Lice Fast at a Lice Salon

    6 Powerful Reasons to Visit a Lice Salon for Fast Relief

    Reasons a Golf Ball Bottle Opener Will Be the Life of Your Next Party

    5 Reasons a Golf Ball Bottle Opener Will Elevate Your Party

    10 Steps to Your Perfect Senior Living Rentals Home!

    10 Steps to Your Perfect Senior Living Rentals Home!

  • Articles
    • Startup
    • Social Media
33 °f
Chicago
35 ° Sat
35 ° Sun
35 ° Mon
37 ° Tue
No Result
View All Result
Daily illinois - USA | News, Sports & Updates Web Magazine
  • News
    • All
    • Business
    • Education
    • Politics
    • Sports
    • World
    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Lifesaving Domestic Violence Resources in Pinellas County

    Lifesaving Domestic Violence Resources in Pinellas County

    Non-Cash Compensations to Keep Employees Motivated!

    4 Powerful Non-Cash Compensations to Keep Employees Motivated!

    Brand Awareness Measurement Strategies

    8 Proven Brand Awareness Measurement Strategies to Grow

    Eco-Friendly Bubble Mailers: Boost Green Brand Reputation

    Eco-Friendly Bubble Mailers: Elevate Your Green Brand Reputation

    Unlock Faster App Development with Automation Testing

    Unlock Automation Testing to Master Faster App Development

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Highlights of AFC Asian Cup Qatar

    Highlights of AFC Asian Cup Qatar 2023

    Illinois sets a new record for cannabis sales. Doctors notice an increase in psychotic disorders due to the use of cannabis

    Illinois Sets a New Record for Cannabis Sales. Doctors Notice an Increase in Psychotic Disorders Due to the Use of Cannabis

  • Science & Tech
    • All
    • Ai - Artificial Intelligence
    • Apps
    • Mobile
    Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

    Having trouble with AirDrop? Discover ways to resolve the issue.

    MiniTool ShadowMaker Best Backup Software for Your Data

    MiniTool ShadowMaker Best Backup Software for Your Data

    What exactly is a Snapchat Streak

    What exactly is a Snapchat Streak?

    Access WhatsApp on your iPad through WhatsApp Web.

    Ways to Access WhatsApp on an iPad

    AI and Machine Learning Trends Revolutionizing Security

    7 AI and Machine Learning Trends Revolutionizing Security

    How-to-Lock-Your-Facebook-Profile-on-iPhone,-Android-&-Desktop

    How to Lock Your Facebook Profile on iPhone, Android & Desktop

    How to Log out of Facebook

    Steps to Sign Out of Facebook

    How to Know If Someone Blocked You on Snapchat

    How to Know If Someone Blocked You on Snapchat

    How to Update Apps on iPhone (2024 Guide)

    How to Update Apps on iPhone

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Castle

    10 Awesome Projects to Create in Minecraft

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft.png

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    How Immersive Gaming & VR are Shaping PC Gaming's Future

    How Immersive Gaming & VR are Shaping PC Gaming’s Future

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Dance Studios in to Get Cheap Dance Classes in Chicago

    9 Dance Studios in to Get Cheap Dance Classes in Chicago

    Video Game

    Video Game Workers Must Continue to Join Unions in 2024

    Exploring the Free Best Websites Online Games

    Exploring the Free Best Websites Online Games

    • F95zone
  • Lifestyle
    • All
    • Fashion
    • Food
    • Travel
    Top Caption Selfie Hacks to Boost Your Engagement Fast!

    10 Best Caption Selfie Hacks to Boost Your Engagement Fast!

    Understanding Ear Wax Build-Up With Causes & Solutions

    Top 5 Ways to Prevent Ear Wax Build-Up Naturally

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To.jpg

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To

    Tips for Choosing Furniture: Creating a Space that Reflects You

    Tips for Choosing Furniture: Creating a Space that Reflects You

    5 Ways Pool Liners Boost Energy Efficiency

    Save Money: 5 Ways Pool Liners Boost Energy Efficiency

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Fat Reduction Treatments to Sculpt Your Dream Body!

    2 Best Fat Reduction Treatments to Sculpt Your Dream Body!

    Proven Steps to Get Rid of Lice Fast at a Lice Salon

    6 Powerful Reasons to Visit a Lice Salon for Fast Relief

    Reasons a Golf Ball Bottle Opener Will Be the Life of Your Next Party

    5 Reasons a Golf Ball Bottle Opener Will Elevate Your Party

    10 Steps to Your Perfect Senior Living Rentals Home!

    10 Steps to Your Perfect Senior Living Rentals Home!

  • Articles
    • Startup
    • Social Media
No Result
View All Result
Daily illinois - USA | News, Sports & Updates Web Magazine
No Result
View All Result
Home Science & Tech

Actors behind PyPI supply chain attack have been active since late 2021

by admin
December 5, 2022
in Science & Tech
0
Hackers are exploiting a server vulnerability with a severity of 9.8 out of 10
493
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

The official software repository for the Python language, Python Package Index (PyPI), has been targeted in a complex supply chain attack that appears to have successfully poisoned at least two legitimate projects with credential-stealing malware, researchers said on Thursday.

PyPI officials said last week that project contributors were under a phishing attack that attempted to trick them into divulging their account login credentials. When successful, the phishers used the compromised credentials to publish malware that posed as the latest release for legitimate projects associated with the account. PyPI quickly took down the compromised updates and urged all contributors to use phishing-resistant forms of two-factor authentication to protect their accounts better.

Today we received reports of a phishing campaign targeting PyPI users. This is the first known phishing attack against PyPI.

We’re publishing the details here to raise awareness of what is likely an ongoing threat.

— Python Package Index (@pypi) August 24, 2022

On Thursday, researchers from security firms SentinelOne and Checkmarx said that the supply chain attacks were part of a larger campaign by a group that has been active since at least late last year to spread credential-stealing malware the researchers are dubbing JuiceStealer. Initially, JuiceStealer was spread through a technique known as typosquatting, in which the threat actors seeded PyPI with hundreds of packages that closely resembled the names of well-established ones, in the hopes that some users would accidentally install them.

Advertisement

RelatedPosts

Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

Having trouble with AirDrop? Discover ways to resolve the issue.

January 21, 2025
MiniTool ShadowMaker Best Backup Software for Your Data

MiniTool ShadowMaker Best Backup Software for Your Data

January 18, 2025
What exactly is a Snapchat Streak

What exactly is a Snapchat Streak?

December 27, 2024
Access WhatsApp on your iPad through WhatsApp Web.

Ways to Access WhatsApp on an iPad

December 26, 2024

JuiceStealer was discovered on VirusTotal in February when someone, possibly the threat actor, submitted a Python app that surreptitiously installed the malware. JuiceStealer is developed using the .Net programming framework. It searches for passwords stored by Google Chrome. Based on information gleaned from the code, the researchers have linked the malware to activity that began in late 2021 and has evolved since then. One likely connection is to Nowblox, a scam website that purported to offer free Robux, the online currency for the game Roblox.

Over time, the threat actor, which the researchers are calling JuiceLedger, started using crypto-themed fraudulent applications such as the Tesla Trading bot, which was delivered in zip files accompanying additional legitimate software.

“JuiceLedger appears to have evolved very quickly from opportunistic, small-scale infections only a few months ago to conducting a supply chain attack on a major software distributor,” the researchers wrote in a post. “The escalation in complexity in the attack on PyPI contributors, involving a targeted phishing campaign, hundreds of typosquatted packages and account takeovers of trusted developers, indicates that the threat actor has time and resources at their disposal.”

PyPI has begun offering contributors free hardware-based keys for use in providing a second, unphishable factor of authentication. All contributors should switch to this stronger form of 2FA immediately. People downloading packages from PyPI—or any other open source repository—should take extra care to ensure the software they’re downloading is legitimate.

Source by arstechnica.com

Related

Related Posts

How to Remove a Playlist from Spotify

How to Remove a Playlist from Spotify

March 21, 2022
Xuetong-responds-to-170-million-suspected-data-leakage

Xuetong responds to 170 million suspected data leakage

November 20, 2022
Unlocking the Power of Symbols in Instagram Bio

Unlocking the Power of Symbols in Instagram Bio

October 21, 2023
What exactly is a Snapchat Streak

What exactly is a Snapchat Streak?

December 27, 2024

Trending

  • How to Clone NVMe to NVMe SSD Without Reinstalling
  • Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of
  • Having trouble with AirDrop? Discover ways to resolve the issue.
  • 10 Awesome Projects to Create in Minecraft
  • A Guide to Acquiring and Utilizing Command Blocks in Minecraft
  • MiniTool ShadowMaker Best Backup Software for Your Data
  • 10 Best Caption Selfie Hacks to Boost Your Engagement Fast!
Daily illinois

© 2025 Dailyillinos.com

Navigate Site

  • Daily Illinois
  • About
  • Contact
  • Privacy
  • Terms
  • DMCA
  • Sitemap
  • Write For Us

Follow Us

No Result
View All Result
  • About Us Page
  • Contact
  • Daily illinois
  • DMCA Policy
  • Privacy Policy
  • Submit, Guest Post, Write For Us and Become a Contributor
  • Terms of Use

© 2025 Dailyillinos.com

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.