Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
Google is racing to contain the fallout after tens of millions of stolen Gmail logins were found circulating online, tied to ...