Bad Actors Are Joining the AI Revolution: Here’s What We’ve Found in the Wild
hackernoon.com
hackernoon.com
"As an unintended consequence of these activities, the resilient open-source registries we rely on are facing an overburden of resources. Last month alone our security researchers confirmed as malicious a whooping 6,933 packages uploaded to the npm and PyPI registries.
We recently tracked the campaign of a Spanish-speaking group called EsqueleSquad which has uploaded more than 5,000 packages to PyPI. "
Holy shit this is scary. I think what's scarier is that for someone who's been using Python for over 7 years, this is not something I had to worry before.