MacOS devices are being attacked with a PyPI backdoor to sneak into corporate networks

Security researchers have detected a new campaign that seeks to gain access to corporate networks by targeting macOS devices and using PyPI spoofing/typing and steganography to compromise endpoints.

Phylum researchers, who first observed the attack, anonymous threat actors created what appears to be a fork of the “requests” library in the Python Package Index (PyPI).

scroll to top