GitHub Token Leak Exposes Python's Core Repositories to Potential Attacks
ID: ada7a218-bc19-5a97-9c32-de3d40597b39
STIX ID: report--ada7a218-bc19-5a97-9c32-de3d40597b39
Feed Name: The Hacker News
Researchers discovered an accidentally leaked GitHub Personal Access Token embedded in a public Docker container that could have allowed an attacker to modify Python core repositories and PyPI packages; the token was revoked after responsible disclosure and there is no evidence of exploitation. In addition, Checkmarx found malicious PyPI packages (testbrojct2, proxyfullscraper, proxyalhttp, proxyfullscrapers) that scan for files and exfiltrate data to a Telegram bot linked to cybercriminal operations, indicating active infostealer malware on the package registry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
