techy @techy.detectionengineering.net · Dec 7

If indeed the problem is pushing malicious code and publishing directly to PyPi itself, there's only one listed account owner (though there could be more): Glenn Jocher. Email listed directly on PyPi. If someone got access to this email, you could search for it inside infostealer or breach databases

1 likes 1 replies

?

Replies

techy · Dec 7

There's an excellent writeup on the attack chain via the vulnerability here bsky.app/profile/yoss... . Thank you @yossarian.net!