Legacy Python Packages Expose Risk of PyPI Supply Chain Attacks
- Details
- Parent Category: News:
- Category: Risk Management
Cybersecurity researchers have uncovered vulnerable code embedded in several legacy Python packages, raising concerns about potential supply chain attacks against the Python Package Index (PyPI). The issue stems from a domain takeover risk linked to outdated bootstrap scripts used by the build automation tool zc.buildout. According to ReversingLabs, these scripts still reference a long-abandoned domain, python-distribute[.]org, which is now available for purchase.