vulnerablecode
vulnerablecode copied to clipboard
Collect some PyPI malicious packages
The data from this Slovak agency https://www.nbu.gov.sk/skcsirt-sa-20170909-pypi/ seems intersting and not always in CVE
This SK CSIRT does not seem to public advisories consistently. But https://github.com/hrbrmstr/pypi-malicious-packages/tree/master/data has some historical malicious PyPI packages that we should collect.