malicious-pypi-package-masquerades-as-chimera-module-to-steal-aws,-ci/cd,-and-macos-data

Cybersecurity analysts have identified a harmful package within the Python Package Index (PyPI) repository that can extract sensitive information related to developers, including credentials, configuration details, and environment variables, among other data. The package, referred to as chimera-sandbox-extensions, garnered 143 downloads and is likely aimed at individuals utilizing a service named Chimera Sandbox.


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This