Tagged articles
1 articles
Page 1 of 1
21CTO
21CTO
Jun 21, 2025 · Information Security

Malicious Python Packages Hijacking Open‑Source Repos: The Banana Squad Threat

Security researchers at ReversingLabs have uncovered a coordinated campaign by the “Banana Squad” that injects malicious Python toolkits into hundreds of seemingly legitimate open‑source GitHub repositories, using domain squatting, repository impersonation, and hidden code obfuscation to steal sensitive data and evade detection.

GitHubReversingLabsmalicious Python packages
0 likes · 5 min read
Malicious Python Packages Hijacking Open‑Source Repos: The Banana Squad Threat