TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Lobsters — security tag

What's new in pip 26.1 - lockfiles and dependency cooldowns

ichard26.github.io via ubernostrum · 2026-04-27 · Read original ↗

ATT&CK techniques detected

1 predictions
T1059.006Python
59%
“i. e. when given to the stdlib zipfile. is _ zipfile ( ) function, it will return true. on pip 26. 0 and older, pip will ignore the. tar. gz contents and use the zip contents instead. this can be abused to easily obfuscate malicious code. pip 26. 1 updates the logic used to disam…”

Summary

Comments