There’s another malicious PyPl package – this one stealing data from developers

Criminals have been found impersonating a well-known cybersecurity firm in an attempt to steal data from software developers, researchers have found.

Researchers from ReversingLabs recently discovered a malicious Python (opens in new tab) package on PyPI called “SentinelOne”. Named after a known cybersecurity company from the United States, the package pretends to be a legitimate SDK client allowing easy access to the SentinelOne API from within a separate project. 

Source