Malicious PyPI Package Masquerades as Chimera Module to Steal AWS, CI/CD, and macOS Data
June 16, 2025
1 min read
●
The Hacker News

The package, named chimera-sandbox-extensions, attracted 143 downloads and likely targets users of a service called Chimera Sandbox. It's capable of harvesting sensitive developer-related information, such as credentials and configuration data.