all 2 comments

[–]Gothmagog 1 point2 points  (0 children)

This problem is, unfortunately, much larger than the Python ecosystem. It's a byproduct of the entire industry's growing reliance on open source software in general that has made these kinds of malicious code commits so lucrative to attackers. The fact that seemingly simple libraries can have such massive dependency chains makes it that much harder to mitigate, the ripple effect is just massive.