HNHacker News
TopNewBestAskShowJobs

keyP

416 karma · joined December 3, 2019

submissionscomments
keyP··on Two malicious Python libraries caught stealing SSH and GPG keys
There's a bit more to it as "dateutil" is actually installed via "pip install python-dateutil", not simply "pip install dateutil". If someone was to see "python3-dateutil", there's every chance they think it's the same module but with Python3 compatibility.
keyP··on Two malicious Python libraries caught stealing SSH and GPG keys
Agreed, although I think there's more than just a comparing spelling issue here. "dateutil" via pip is installed using "pip install python-dateutil". I can easily see someone thinking "python3-dateutil" is simply a Py3 compatible version of "python-dateutil". The "python3-dateutil" module imported "jeIlyfish" so my guess is that the creator banked more on people installing the fake dateutil library than directly downloading jeIlyfish.
← PreviousPage 3 of 3