Security News Carding tool abusing WooCommerce API downloaded 34K times on PyPI BleepingComputer Daniel Bender 06 Apr 2025 A newly discovered malicious PyPi package named 'disgrasya' that abuses legitimate WooCommerce stores for validating stolen credit cards has been downloaded over 34,000 times from the open-source package platform.