Skip to content

Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparent

Comments

Still good to raise awareness but a slight bit of scaremongering

It's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech:

using our latest open source tool, GuardDog, which uses heuristics to identify malicious or compromised PyPI packages.
We recently released GuardDog, a free and open-source tool to identify malicious PyPI packages
Datadog ASM Vulnerability Monitoring, announced earlier this year at Dash, allows you to identify vulnerable and malicious packages
Datadog Cloud Workload Security has a number of out-of-the-box rules to detect post exploitation scenarios
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.