PyPI package security
A PyPI source distribution can execute code while it installs, not when you import it. Extuno analyzes wheels and sdists, then runs that install path in a sandbox. It flags install-time code execution, typosquatted names, and updates that turn malicious.
What makes PyPI packages risky?
A source distribution runs setup.py during installation, so the code executes before anything imports the package. Typosquatting is how an attacker gets into that install path. One wrong character in a requirements file and the payload runs with the rest of the install.
What does Extuno check on PyPI?
Install-time code execution, network calls and credential reads during install, obfuscated payloads, typosquatting of popular package names, and the poisoned-update pattern across versions.
How does the sandbox handle setup.py?
Extuno runs the install in an ephemeral, network-segmented micro-VM and records process, network, and file behavior, so a malicious setup.py is observed with its endpoint and payload instead of running on your machine.