Malicious PyPI Package Removes netstat, Tampers with SSH Config

A recent report by Sonatype security researcher Ax Sharma highlights newly discovered malicious packages on the PyPI registry, including , which can install the Meterpreter trojan disguised as pip, delete the system utility, and tamper with SSH file. Named after the popular audio codec developed by Qualcomm and used in many Bluetooth devices, is not the only new threat identified on PyPI.

Read full article on InfoQ


