Malicious Python libraries stealing OpenPGP and SSH keys:
– Look for python3-dateutil, and jeIlyfish.
– Both modules try to exfiltrate SSH/OpenPGP keys and send them to an IP address.
– This is the third time the PyPI team intervenes to remove typo-squatted malicious Python libraries from the official repository.
This is the social network for Conesphere.com's community.