2 Followers
33 Following
8 Posts
We Stop Malicious Open Source Code | Protecting your software supply chain | SSCS
Websiteossprey.com
BSky‪@ossprey.bsky.social‬
Xwww.x.com/osspreysecurity

A new .wav of #TeamPCP malware embedded in #telnyx versions 4.87.1 and 4.87.2 on #PyPI.

Full analysis is on our blog.

If telnyx is in your dependency tree, check your installed version now.

https://ossprey.com/blog/telnyx-pypi-malware-wav/

#SupplyChainSecurity #PyPI #OpenSource

OSSPREY

New from Ossprey: PyPI is cracking down on domain resurrection attacks by invalidating expired maintainer domains.

1,800 accounts un-verified in just 2 months.
Time to check if your dependencies rely on revoked maintainers.

Full blog: ossprey.com/blog/pypi-domain-vigilance

#opensourcesecurity

curl is just the hobby

Jan Gampe took things to the next level by actually making this cross-stitch out of the pattern I previously posted online. The flowers really gave it an extra level of charm I think. As a cross-stitch As a pillow This quote is from a comment by an upset user on my blog, replying to one … Continue reading curl is just the hobby →

daniel.haxx.se