all InfoSec news
Users of Telegram, AWS, and Alibaba Cloud targeted in latest supply chain attack
Oct. 12, 2023, 11:05 a.m. | MalBot
Malware Analysis, News and Indicators - Latest topics malware.news
Key Points
- Throughout September 2023, an attacker executed a targeted campaign via Pypi to draw developers using Alibaba cloud services, AWS, and Telegram to their malicious packages.
- Rather than performing automatic execution, the malicious code within these packages was strategically hidden within functions, designed to trigger only when these functions were called.
- The Attackers leveraged Typosquatting and Starjacking techniques to lure developers to their malicious packages.
- One of the malicious packages, mimicking a popular repo, capitalized on its absence from …
alibaba alibaba cloud attack attacker automatic aws campaign cloud cloud services code developers functions hidden key key points latest malicious malicious packages packages performing points pypi september services supply supply chain supply chain attack telegram trigger
More from malware.news / Malware Analysis, News and Indicators - Latest topics
Jobs in InfoSec / Cybersecurity
Senior Security Specialist, Forsah Technical and Vocational Education and Training (Forsah TVET) (NEW)
@ IREX | Ramallah, West Bank, Palestinian National Authority
Consultant(e) Junior Cybersécurité
@ Sia Partners | Paris, France
Senior Network Security Engineer
@ NielsenIQ | Mexico City, Mexico
Senior Consultant, Payment Intelligence
@ Visa | Washington, DC, United States
Corporate Counsel, Compliance
@ Okta | San Francisco, CA; Bellevue, WA; Chicago, IL; New York City; Washington, DC; Austin, TX
Security Operations Engineer
@ Samsara | Remote - US