Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks Emmie Evans August 19, 2025

Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks

Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior through a dependency that allows it to establish persistence and achieve code execution.
The package, named termncolor, realizes its nefarious functionality through a dependency package called colorinal by means of a multi-stage malware operation, Zscaler

Write a comment
Your email address will not be published. Required fields are marked *
Scroll to Top