臥槽!只是pip安裝輸錯字母,就中了挖礦病毒
PyPI里的挖礦軟件
惡意PyPI包防不勝防
使用pip請謹慎
[1]https://blog.sonatype.com/sonatype-catches-new-pypi-cryptomining-malware-via-automated-detection
[2]https://arstechnica.com/gadgets/2021/06/counterfeit-pypi-packages-with-5000-downloads-installed-cryptominers/
[3]https://www.freebuf.com/articles/web/254820.html
[4]https://github.com/rsc-dev/pypi_malware
曉查 發自 凹非寺? 量子位 報道 | 公眾號 QbitAI