"Top Python Developers Hacked in Sophisticated Supply Chain Attack"
"Top Python Developers Hacked in Sophisticated Supply Chain Attack"
Checkmarx reports that multiple Python developers, including a Top.gg maintainer, were infected with information-stealing malware after downloading a malicious clone of a popular tool. Colorama, a tool that makes ANSI escape character sequences work on Windows, has over 150 million monthly downloads. The hackers cloned the tool, inserted malicious code into it, and put the malicious version on a fake mirror domain that used typosquatting to trick developers into thinking it was the legitimate 'files.pythonhosted.org' mirror.