Junglewise Threat Intelligence

PYSEC-2022-199 - The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code

Severity: info · Published 2022-05-24

Technologies: ctx (PyPI). Vendors: PyPI.

Executive brief

The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.

Affected products

  • PyPI ctx

Related threats