Two fake spellchecker packages on PyPI hid a Python RAT in dictionary files, activating malware on import in version 1.2.0.
As packages pile up on doorsteps across the country, criminals are taking advantage of the busy delivery season by sending convincing fake texts, emails and even making in-person visits, demanding ...