eupolicy.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
This Mastodon server is a friendly and respectful discussion space for people working in areas related to EU policy. When you request to create an account, please tell us something about you.

Server stats:

218
active users

#pypi

2 posts2 participants0 posts today

I enjoyed writing my first blog post last weekend, so I thought I'd write another one. This one is about a #bash script that became a #Python script and is now a package. All because I was too lazy to label plates and tubes in the lab by hand. The post is mostly about the history and motivation behind the package, i.e. the stuff that does't really fit into the README

gl-eb.me/blog/posts/2025-05-25

A hex sticker with a yellow border as well as white background with light grey, rectangular outlines of labels. The package name generate-labels is written across the sticker.
Gleb EbertGenerating Printable Labels – Gleb Ebert
More from Gleb Ebert
#quarto#foss#Pypi

Backdoor implant discovered on PyPI posing as debugging utility

A sophisticated malicious package named 'dbgpkg' was detected on PyPI, masquerading as a Python debugging utility. The package implants a backdoor on systems, enabling execution of malicious code and data exfiltration. It uses function wrapping techniques to evade detection and is believed to be part of a larger campaign possibly linked to a hacktivist group known as Phoenix Hyena. The campaign also includes other packages like 'discordpydebug' and 'requestsdev'. The attackers' motivation appears to be geopolitical, potentially related to the Russia-Ukraine conflict. The use of specific backdooring techniques and tools like Global Socket Toolkit indicates a high level of sophistication and an intent to establish long-term presence on compromised systems.

Pulse ID: 68264a9cb2b105513148d978
Pulse Link: otx.alienvault.com/pulse/68264
Pulse Author: AlienVault
Created: 2025-05-15 20:12:12

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

There are currently 636,000 #python projects on #pypi

By the time you read this there will be several more, to the tune of one every few minutes

#opensource tools, algorithms, frameworks for #datascience, #machinelearning, #webdev and much, much more, in principle accessible to everybody

What does this mean, where will this lead?

Your guess as good as mine. But this is emphatically *not* the world we used to live-in, until recently

Remember this when you are gloomy

pypi.org/

Revolutionizing Collaboration: PyPI Introduces Organization Accounts for Enhanced Package Management

The Python Packaging Index (PyPI) is taking a significant leap forward by introducing organization accounts, designed to streamline collaboration for larger teams and projects. This move not only enha...

news.lavx.hu/article/revolutio

While preparing my talk, I found some (small) accessibility issues in pypi warehouse project but seems like only maintainers can raise issues and I don't know what to do now, other type of issues doesn't seems to fit.
Is there someone here I can talk to about that and eventually help for the fix?