Gmail servers hijacked by malicious PyPI packages to spread havoc – here’s how to stay safe

May Be Interested In:AI paper mills are swamping science with garbage studies




  • Socket found seven malicious packages on PyPI
  • The packages were abusing Gmail and WebSocket
  • They were removed from the platform

Several malicious PyPI packages were recently observed abusing Gmail to exfiltrate stolen sensitive data and communicate with their operators.

Cybersecurity researchers Socket, who found the packages, reported them to the Python repository and thus helped get them removed from the platform – however the damage has already been done.

share Share facebook pinterest whatsapp x print

Similar Content

Firefox logo on multi colored background
Firefox surprises no one by adding AI to the browser
Best iPhone 16 Deals: Upgrade to Apple's Latest Phone Ahead of New Year's Eve With These Deals
Best iPhone 16 Deals: Upgrade to Apple's Latest Phone Ahead of New Year's Eve With These Deals
The 20 Best Halloween TV Episodes of All Time
The 20 Best Halloween TV Episodes of All Time
Black Monday, COVID-19: Here are some of the market’s biggest drops
Black Monday, COVID-19: Here are some of the market’s biggest drops
Birmingham Live
Man Utd’s Jim Ratcliffe reacts to Marcus Rashford’s Aston Villa transfer
Angie Stone, Grammy-nominated R&B singer, dead at 63 | CBC News
Angie Stone, Grammy-nominated R&B singer, dead at 63 | CBC News
Global Focus: Events that Define Our World | © 2025 | Daily News