Summary
A coordinated supply chain attack targeting Python packages on PyPI has been identified, which involves typosquatting of popular libraries like Flask and Requests. The attack introduced malicious packages that execute harmful code when installed without user awareness. The malware, reminiscent of a previous npm variant, steals credentials and propagates itself throughout CI/CD environments. GitLab's Vulnerability Research team shares details on the attack's execution, the behavior of the malicious packages, and remediation steps for affected developers.