News

[Bertus] broke a story about a malicious Python package called ... There is a legitimate package named “Colorama” that takes ANSI color commands, and translates them to the Windows terminal.
The attackers chose to trojanize a legitimate Python package called Colorama that has over 150 ... identified included yocolor, coloriv, colors-it, pylo-color, and others with random looking ...
Earlier this week, Checkmarx reported a separate supply-chain attack that also targeted Python developers. The actors in that attack cloned the Colorama tool, hid malicious code inside ...