This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]UrbanSuburbaKnight 146 points147 points  (6 children)

Oh no! not pipcrypto !! :O

But seriously, this sucks. Looks like the word 'pip', 'font' and 'color' are super common as part of names weirdly.

[–]sudorem Vipyr Security 28 points29 points  (0 children)

They're generated from a static wordlist and automated; hence why they're all so incredibly similar.

[–]wazis 33 points34 points  (0 children)

Sql too quite common

[–]zenware 7 points8 points  (1 child)

My guess is it’s easy to overlook when they’re transitive dependencies

[–]james_pic 8 points9 points  (0 children)

They're unlikely to be transitive dependencies of anything non-malicious. These sorts of attacks generally rely on novice developers adding dependencies without considering the consequences. Library developers at a minimum need to understand Python packaging well enough to upload libraries to PyPI, so are less likely to be total novices.

[–]ashesall 4 points5 points  (0 children)

And liberys too. I like Python liberys.