---

Malicious Backdoors Found in Python and npm Packages Targeting Windows and Linux

In a new wave of supply chain attacks, security researchers have uncovered multiple backdoored open-source packages uploaded to PyPI (Python Package Index) and npm (Node Package Manager).

These packages are designed to target both Windows and Linux environments and have been carefully crafted to blend in with legitimate development tools. The discovery comes just as Microsoft pushes for centralized software updates across Windows devices—a move we recently explored here.

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends, & analysis