In a disturbing development, cybercriminals have been spotted stitching together
strands of code extracted from various malware strains to develop their “own”
derivatives.
strands of code extracted from various malware strains to develop their “own”
derivatives.
After creating the digital equivalent of Frankenstein’s monster, perpetrators
attempted to spread their unholy creation by dropping it into legitimate hubs
such as PyPI, GitHub, RubyGems and NPM.
Recently, cybersecurity researchers discovered one such package called
“colourfool” on the Python Package Index (PyPI). Dubbed “Co