WhisperX tag archive

#pypi

This page collects WhisperX intelligence signals tagged #pypi. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (10)

The Lab · 2026-03-30 18:26:58 · The Register

1. PyPI Poisoning: Trivy Attackers Strike Again with Malicious Telnyx Package

The threat actors behind the recent Trivy supply-chain breach have escalated their campaign, now poisoning the Python Package Index (PyPI) with malicious versions of the Telnyx SDK. This latest attack aims to infect developers' systems with credential-stealing malware, marking a continued and aggressive exploitation of...

The Lab · 2026-04-26 14:54:07 · GitHub Issues

2. Gateway Framework Auto-Installs Unsigned Python Packages, Raising Critical Supply Chain Risk

A critical supply chain vulnerability has been identified in a gateway framework that automatically installs missing Python packages without verification. The flaw, documented in a security disclosure, stems from code that attempts to install dependencies like flask, requests, and flask-cors via subprocess on import if...

The Lab · 2026-04-27 23:54:09 · GitHub Issues

3. Critical Path Traversal Vulnerability in Python setuptools Enables Arbitrary File Write — CVE-2025-47273

A path traversal vulnerability in setuptools' PackageIndex.download function allows remote attackers to write files to arbitrary locations on a target system. The flaw, tracked as CVE-2025-47273 and assigned GHSA-5rjg-fvgr-3xxf, was addressed in version 78.1.1, prompting an urgent dependency update from the prior v70.0...

The Lab · 2026-05-08 04:16:12 · The Hacker News

4. Three PyPI Packages Caught Stealthily Deploying ZiChatBot Malware on Windows and Linux Systems

Security researchers at Kaspersky have uncovered a supply-chain threat targeting developers on PyPI, the dominant Python package repository. Three malicious packages were found implementing their advertised functionality while simultaneously delivering a previously undocumented malware family dubbed ZiChatBot, capable ...

The Lab · 2026-05-12 09:48:22 · The Hacker News Echo RSS

5. TeamPCP's Mini Shai-Hulud Campaign Infiltrates TanStack, Mistral AI, UiPath, OpenSearch and Guardrails AI in Coordinated Supply Chain Attack

A threat actor identified as TeamPCP has launched a sophisticated supply chain attack campaign, dubbed "Mini Shai-Hulud," targeting npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI. The campaign represents a significant escalation in the actor's ongoing campaign against software de...

The Vault · 2026-05-12 12:48:18 · BleepingComputer Echo RSS

6. Shai-Hulud Campaign Compromises Hundreds of npm and PyPI Packages with Credential-Stealing Malware

A sophisticated supply-chain attack campaign dubbed "Shai-Hulud" has compromised hundreds of packages across the npm and PyPI package registries, distributing credential-stealing malware directly into developer environments. The campaign represents a calculated targeting of the software development ecosystem, exploitin...

The Lab · 2026-05-12 16:18:29 · Techmeme Echo RSS

7. Microsoft Probes Compromised Mistral AI PyPI Package Tied to Mini Shai-Hulud Supply Chain Attack

Microsoft has initiated an investigation into a compromised Python package uploaded to the Python Package Index (PyPI) under the Mistral AI branding. Security researchers have confirmed the malicious package, identified as version 2.4.6, is connected to the broader Mini Shai-Hulud supply chain campaign, highlighting th...

The Lab · 2026-05-12 16:48:26 · Mastodon:hachyderm.io:#infosec

8. TanStack and 160+ npm/PyPI Packages Hit in Self-Spreading Supply Chain Worm Attack

A sophisticated supply chain attack has compromised TanStack and over 160 packages across the npm and PyPI ecosystems, security researchers at Orca Security report. The attack, characterized as a self-propagating worm, represents a significant escalation in software supply chain threats, targeting widely-used developer...

The Lab · 2026-05-12 19:18:29 · VentureBeat

9. npm Supply Chain Worm Harvests Developer Credentials, Persists After Package Removal

A sophisticated supply chain attack campaign has compromised 172 npm and PyPI packages since May 11, embedding a credential-harvesting worm that survives package removal on affected development workstations. Security researchers warn that any environment that installed or imported these packages should be treated as co...

The Lab · 2026-05-14 13:18:27 · Mastodon:mastodon.social:#infosec

10. TeamPCP Claims Mistral AI Breach While Company Confirms TanStack Supply Chain Compromise

A threat actor identifying as TeamPCP has claimed responsibility for breaching Mistral AI, the French artificial intelligence company confirmed on Tuesday, in an incident that remains under active investigation. The company simultaneously disclosed that it was impacted by the TanStack supply chain attack, which involve...