Phylum Research Team

Phylum Research Team

Hackers, Data Scientists, and Engineers responsible for the identification and takedown of software supply chain attackers.

June’s Sophisticated npm Attack Attributed to North Korea

In June 2023, Phylum was the first to unearth a series of suspicious npm publications belonging to what appeared to be a highly targeted attack. The identified packages, published in pairs, required installation in a specific

Phylum Discovers Sophisticated Ongoing Attack on NPM

🚨Jul 22, 2023 Update: This attack has now been attributed to North Korean nation-state actors. Click here to learn more. On June 11, Phylum’s automated risk detection platform alerted us to a peculiar pattern of

PyPI New Account Suspension Pauses Attacks

PyPI suspended new account registration for about 30 hours over this past weekend because malicious attacks exceeded the human bandwidth available among the PyPI administrators to properly deal with them. For the moment, this action thwarted

Respawning Malware Persists on PyPI

A bad actor on GitHub continually respawns his malware immediately after PyPI takes it down.

Phylum Detects Suspicious Publications Surrounding Popular Python Package Flask

On the morning of May 10, 2023, Phylum’s automated risk detection platform flagged a series of publications surrounding the popular Flask package on PyPI. After reaching out to the author, we discovered that they were