Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparentComments−capableweb3yStill good to raise awareness but a slight bit of scaremongeringIt's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech:using our latest open source tool, GuardDog, which uses heuristics to identify malicious or compromised PyPI packages.We recently released GuardDog, a free and open-source tool to identify malicious PyPI packagesDatadog ASM Vulnerability Monitoring, announced earlier this year at Dash, allows you to identify vulnerable and malicious packagesDatadog Cloud Workload Security has a number of out-of-the-box rules to detect post exploitation scenarios
Comments
It's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech: