Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
North Korea is doubling down on a familiar playbook by weaponizing trust in open-source software and developer workflows. The ...