A supposedly handy Discord debug tool on PyPI was actually a sneaky RAT, amassing over 11,000 downloads before being pulled. How did this stealth attack slip into our trusted open-source supply chain?
A supposedly handy Discord debug tool on PyPI was actually a sneaky RAT, amassing over 11,000 downloads before being pulled. How did this stealth attack slip into our trusted open-source supply chain?