Malicious Python libraries stealing OpenPGP and SSH keys:


– Look for python3-dateutil, and jeIlyfish.
– Both modules try to exfiltrate SSH/OpenPGP keys and send them to an IP address.
– This is the third time the PyPI team intervenes to remove typo-squatted malicious Python libraries from the official repository.

#python #malware #pypi #infosec #security #cybersecurity

It’s clear, once you start running tracking protection, that the "AI" of #reCAPTCHA is basically that if you do not present tracking cookies, you're suspect. If your site is using #reCAPCHA it should be shunned accordingly. #surveillancecapitalism

