Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
Stranger Things concept of the “Upside Down” is a useful way to think about the risks lurking in the software we all rely on.
With the PyArrow library installed, pandas 3.0 interprets string columns automatically as the str data type instead of NumPy- ...
Veracode announced key platform innovations introduced through the second half of 2025, providing preventive control for software supply chains.
According to the firm’s latest supply chain security report, there was a 73% increase in detections of malicious open-source packages in 2025. The past year also saw a huge jump in the scope of ...