Junglewise Threat Intelligence

CVE-2022-41383: PYSEC-2022-43042 - The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The bac

CVE-2022-41383 · Severity: info · Published 2022-10-11

Technologies: democritus-file-system (PyPI). Vendors: PyPI.

Executive brief

The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

Affected products

  • PyPI democritus-file-system
  • PyPI d8s-archives

Related threats