Typosquatting Attack on ‘Requests’ Python package
medium.com
medium.com
As stodgy and unsexy as the tooling is, the bits relating to dependency resolution and publishing in Maven are the industry gold standard.
https://www.reddit.com/r/Python/comments/bklroc/why_im_not_c...
And every time this happens I will ask for the same thing, I want a platform that has library level isolation and fire-walling.
Also could all PAASs please implement outbound firewalls, I cannot understand why it's not a standard feature.
Squatting is a problem as old as [NSFW] white house dot com versus [official] whitehouse.gov from the 2000s
[1] https://urlscan.io/result/e816e673-edf2-4177-9d3f-ac9a71c826...
"Attacks don't stop, they only get better" is a quote i cant attribute right now but very fitting fitting to the current supply chain situation.
It is good that awareness is rising, which is why i appreciate the blog post.
People with MacBooks that have butterfly keyboards that love to repeat letters for no reason.