Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Robinhood’s startup fund stumbles in NYSE debut

    March 7, 2026

    City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A

    March 6, 2026

    Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year

    March 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Robinhood’s startup fund stumbles in NYSE debut
    • City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A
    • Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year
    • DiligenceSquared uses AI, voice agents to make M&A research affordable
    • Science Corp. raises $230M as it races to bring its brain implant to market
    • Hardware testing startup Nominal hits $1B valuation, raises $155M in 10 months
    • EXCLUSIVE: Luma launches creative AI agents powered by its new ‘Unified Intelligence’ models
    • Zeno raises $25M to speed up production of its battery-swap motorbikes
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets
    Security

    Malicious PyPI package targets Chimera users to steal AWS tokens, CI/CD secrets

    TechurzBy TechurzJune 17, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hacker
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A malicious Python package posing as a harmless add-on for the Chimera sandbox environment, an integrated machine learning experimentation and development tool, is helping threat actors steal sensitive corporate credentials.

    According to new research findings from software supply chain and DevOps company JFrog, the package “chimera-sandbox-extensions”, recently uploaded to the popular PyPI repository, contains a stealthy, multi-stage info-stealer.

    “The detection of harmful packages, such as chimera-sandbox extensions, on PyPI highlights the significant and widespread risk posed by software supply chain attacks,” said Eric Schwake, director of Cybersecurity Strategy at Salt Security. “The primary threat lies in its ability to collect sensitive developer-related data, including credentials, configuration files, and especially AWS tokens and CI/CD environment variables.”

    This poses a direct risk to corporate and cloud infrastructures, enabling attackers to maliciously access and possibly alter or steal large volumes of data through compromised API credentials, Schwake added.

    AWS Chimera CICD Malicious package PyPI Secrets steal targets tokens users
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGoogle launches production-ready Gemini 2.5 AI models to challenge OpenAI’s enterprise dominance
    Next Article The Interpretable AI playbook: What Anthropic’s research means for your enterprise LLM strategy
    Techurz
    • Website

    Related Posts

    Opinion

    OpenAI allows users to directly adjust ChatGPT’s enthusiasm level

    December 20, 2025
    Opinion

    AI startup Tavus founder says users talk to its AI Santa ‘for hours’ per day

    December 10, 2025
    Opinion

    AWS needs you to believe in AI agents

    December 5, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,286 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202514 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202511 Views
    Our Picks

    Robinhood’s startup fund stumbles in NYSE debut

    March 7, 2026

    City Detect, which uses AI to help cities stay safe and clean, raises $13M Series A

    March 6, 2026

    Cluely CEO Roy Lee admits to publicly lying about revenue numbers last year

    March 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.