Phylum Research Team

Phylum Research Team

Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.

Python Crypto Library Updated to Steal Private Keys

Yesterday, Phylum's automated risk detection platform discovered that the PyPI package aiocpa was updated to include malicious code that steals private keys by exfiltrating them through Telegram when users initialize the crypto library. While

Q3 2024 Evolution of Software Supply Chain Security Report

Software supply chain security faces sophisticated security threats in the open-source ecosystem. Phylum analyzed millions of packages & files. Read more.

Typosquat Campaign Targeting npm Developers

Malware authors have published dozens of typosquat npm packages targeting users of the popular Puppeteer library.

Trojanized Ethers Forks on npm Attempting to Steal Ethereum Private Keys

Software supply chain attack targets open-source developers in npm via malicious packages that steal Ethereum private keys, gain SSH persistence.

North Korea Still Attacking Developers via npm

There's a renewed surge of attacks with obfuscated JavaScript and fake job campaigns to compromise developers and infiltrate companies. See Phylum research.