Malicious Python Package “Fabrice” Steals AWS Credentials via 37,000+ Downloads

Nov 7, 2024 | A malicious Python package called “Fabrice” was typosquatting the popular Fabric SSH automation library, exfiltrating AWS credentials from unsuspecting developers. With over 37,000 downloads on PyPI since 2021, the package used encoded payloads and a VPN-based proxy server to covertly steal data.

[Read the full article]

Newsletter Signup

Stay up-to-date on the latest resources and news from CRITICALSTART.