logo

GitHub Token Leak Exposes Python's Core Repositories to Potential Attacks

ID: ada7a218-bc19-5a97-9c32-de3d40597b39

STIX ID: report--ada7a218-bc19-5a97-9c32-de3d40597b39

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-15

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers discovered an accidentally leaked GitHub Personal Access Token embedded in a public Docker container that could have allowed an attacker to modify Python core repositories and PyPI packages; the token was revoked after responsible disclosure and there is no evidence of exploitation. In addition, Checkmarx found malicious PyPI packages (testbrojct2, proxyfullscraper, proxyalhttp, proxyfullscrapers) that scan for files and exfiltrate data to a Telegram bot linked to cybercriminal operations, indicating active infostealer malware on the package registry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.