PyPI malicious packages using compiled Python code to evade detection

Veröffentlicht am: 01 Juni 2023
auf dem Kanal: Wiredhippie
10
1

Researchers have discovered a new attack on the Python Package Index (PyPI) repository that uses compiled Python code to sidestep detection by application security tools. The vulnerability relates to the fshec2 package and its three files -init, main, and full.pyc. PYC files are compiled bytecode files that are generated by the Python interpreter when a Python program is executed. This allows malicious code to be loaded instead of being imported into the Python import library. Loader scripts such as those discovered in the fshell2 package, Zanki said, contain a minimal amount of Python code and perform a simple action: loading of a compiled Python module. According to the security firm, this exploit leverages the importlib package and the Python binary import file to execute code not present in the .pyc file.

#shorts #techshorts #technews #tech #technology #source file #package #compiled Python code


Auf dieser Seite können Sie das Online-Video PyPI malicious packages using compiled Python code to evade detection mit der Dauer stunde minuten sekunde in guter Qualität ansehen, das der Benutzer Wiredhippie 01 Juni 2023 hochgeladen hat, den Link mit Freunden und Bekannten teilen, dieses Video wurde auf Youtube bereits 10 Mal angesehen und es wurde von 1 den Zuschauern gefallen. Viel Spaß beim Betrachtenden Zuschauern gefallen!