Cybersecurity

GitHub has not removed malicious imitation software after 3 weeks

GitHub has not removed a malicious imitation of a popular software package, despite it being reported 3 weeks ago. The imitation software, which is a copy of the 'reqs' package for Python, is used to steal user credentials. The package was uploaded to GitHub 2 years ago and has been downloaded over 3,700 times. The malicious package was discovered by a researcher who found that it was being used to steal credentials from over 300 users. The researcher reported the issue to GitHub, but the company has not taken action to remove the package.

Read the full article at successfulsoftware.net →