An analyzer has been released that identified 200 malicious packages in NPM and PyPI.
The OpenSSF (Open Source Security Foundation), established by the Linux Foundation and aimed at enhancing the security of open-source software, has introduced an open project called Package Analysis, which develops a system for analyzing the presence of malicious code in packages. The project's code is written in Go and is distributed under the Apache 2.0 license. Preliminary scanning of NPM and PyPI repositories using the proposed toolkit has revealed more […]
