Article 1GMYG Tschacher: Typosquatting programming language package managers

Tschacher: Typosquatting programming language package managers

by
corbet
from LWN.net on (#1GMYG)
Nikolai Tschacher demonstrateshow easy it is to run arbitrary code by way of "typosquatting" uploadsto programming language download sites. "Because everybody canupload any package on PyPi, it is possible to create packages which aretypo versions of popular packages that are prone to be mistyped. And ifsomebody unintentionally installs such a package, the next question comesintuitively: Is it possible to run arbitrary code and take over thecomputer during the installation process of a package?" He tried anexperiment and was able to run a little program that phoned home fromthousands of systems.
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments