Security News Carding tool abusing WooCommerce API downloaded 34K times on PyPI BleepingComputer Daniel Bender Apr 6, 2025 A newly discovered malicious PyPi package named 'disgrasya' that abuses legitimate WooCommerce stores for validating stolen credit cards has been downloaded over 34,000 times from the open-source package platform.