Connect with us

Cyber Security

Python packages with malicious code expose secret AWS credentials

Published

on

https://player.vimeo.com/video/724364681?h=4df3395b6d&badge=0&autopause=0&player_id=0&app_id=58479&dnt=1

Sonatype researchers have discovered Python packages that contain malicious code that peek into and expose secret AWS credentials, network interface information, and environment variables.

All those credentials and metadata then get uploaded to one or more endpoints, and anyone on the web can see this. Going up a directory level showed hundreds of TXT files containing sensitive information and secret.

In this Help Net Security video, Ax Sharma, Senior Security Researcher at Sonatype, explains the situation in more detail.

Source: https://www.helpnetsecurity.com/2022/06/27/python-packages-malicious-code-aws-credentials-video/

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO