
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
github.com/ejected-media/learn-css-layout-online
https://github.com/Ejected-Media/Learn-CSS-Layout-online
https://learn-css-layout-online.appspot.com/
_ ...
~
_ ` Regular, Program Schedule ~
_ ...
~
_ ...
~
🐝🛰️ _ ` says "Starting on April 26, 2027, small state and local governments have to make sure that their web content and mobile apps meet the requirements in the rule"
🐝🛰️ _ ` says "This might mean working with vendors to help ensure they understand these requirements or seeking out vendors with such knowledge"
🐝🛰️ _ ` says "For example, if a town hires an outside web developer to design and build the town’s website, the town needs to make sure that the web developer’s design complies with the web content and mobile app accessibility requirements under the ADA"
🐝🛰️ _ ` says "After this time, you must continue to make sure your state or local government’s web content and mobile apps meet the accessibility requirements"
🐝🛰️ _ ` says "If you have a contract, license, or other arrangement with another entity to provide public services for your government, you still need to make sure that those services comply with Title II"
🐝🛰️ _ ` says "This includes making sure that any web content or mobile apps the other entity provides or posts for your government meet the accessibility requirements in Title II"
https://www.ada.gov/resources/small-entity-compliance-guide/
FAQs
Unknown package
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.