HomeSecurityPython Package Index (PyPI) and GitLab under spam attacks

Python Package Index (PyPI) and GitLab are under spam attacks

Spammers have flooded the Python Package Index (PyPI) portal and the source code hosting site GitLab with malicious content – ​​advertisements for malicious websites and services. The attacks are unrelated.

Python Package Index (PyPI) and GitLab

PyPI

The larger of the two attacks took place on PyPI, the official package repository for the Python programming language and a website that hosts tens of thousands of Python libraries.

Over the past month, spammers have been abusing the fact that anyone can create entries on the PyPI website to create pages for non-existent Python libraries that essentially served as giant SEO ads for various shady websites.

The pages typically contained a series of search engine -friendly keywords for various topics – some of these topics were games, porn , movie streaming and giveaways. At the bottom of the pages was a shortened link that often led to a website that attempted to steal payment card data

Python Package Index (PyPI) and GitLab are under spam attacks

The PyPI team told ZDNet that they know exactly what was going on with the keywords.

"Our administrators are working to address unwanted content," Ewa Jodlowska, executive director of the Python software foundation, told ZDNet on Monday.

Yesterday, many of the spam lists that had been created on the PyPI portal began to be removed, an operation that appears to be ongoing.

Gitlab

However, it seems that another new attack has been detected, this time targeting Gitlab, a website that allows developers and companies to host and synchronize work on source code repositories.

An unknown threat actor appears to have spammed GitLab's Issues Tracker on Sunday and Monday by sending spam emails to account holders. Just like the spam on PyPI, these comments redirected users to shady websites.

Python Package Index (PyPI) and GitLab are under spam attacks

Source code repositories with spam content appear to be a new tactic of spam groups, which in previous years had focused mainly on blogs, forums and news portals, which at frequent intervals see their comment sections flooded with malicious links.

GitLab seems to have been unprepared for this type of attack.

Things are back to normal now, but both incidents show the danger of leaving systems “open” and unprotected on the internet.

Although spam messages are not an impressive method of attack, they seem to be very effective.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS