Embedded Malicious Code in ctx
Critical severity
GitHub Reviewed
Published
Jun 2, 2022
to the GitHub Advisory Database
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Jun 2, 2022
Reviewed
Jun 2, 2022
Last updated
Jan 11, 2023
The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.
References