Aug. 3, 2023, 9:34 p.m. | Karlo Zanki

Security Boulevard securityboulevard.com


ReversingLabs has identified several malicious Python packages on the Python Package Index (PyPI) open source repository. In all, ReversingLabs researchers uncovered 24 malicious packages imitating three, popular open source Python tools: vConnector, a wrapper module for pyVmomi VMware vSphere bindings; as well as eth-tester, a collection of tools for testing ethereum based applications; and databases, a tool that gives asyncro support for a range of databases.


The post VMConnect: Malicious PyPI packages imitate popular open source …

collection dev & devsecops eth ethereum malicious malicious packages modules open source package packages popular pypi pypi packages python python package python package index python tools repository researchers reversinglabs software supply chain security testing threat research tools vmware vmware vsphere vsphere wrapper

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)