Python packages with malicious code expose secret AWS credentials

Amazon Web Services AWS cybercrime Cybersecurity Don't miss Hot stuff Python Research Sonatype Video

Sonatype researchers have discovered Python packages that contain malicious code that peek into and expose secret AWS credentials, network interface information, and environment variables. All those credentials and metadata then get uploaded to one or more endpoints, and anyone on the web can see this. Going up a directory level showed hundreds of TXT files containing sensitive information and secret. In this Help Net Security video, Ax Sharma, Senior Security Researcher at Sonatype, explains the … More

The post Python packages with malicious code expose secret AWS credentials appeared first on Help Net Security.