{"id":"GHSA-4g82-3jcr-q52w","summary":"Malware in ctx","details":"The `ctx` hosted project on [PyPI](https://pypi.org/project/ctx/) was taken over via user account compromise and replaced with a malicious project which contained runtime code that collected the content of `os.environ.items()` when instantiating `Ctx` objects. The captured environment variables were sent as a base64 encoded query parameter to a heroku application running at `https://anti-theft-web.herokuapp.com`.\n\nIf you installed the package between May 14, 2022 and May 24, 2022, and your environment variables contain sensitive data like passwords and API keys (like `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`), we advise you to rotate your passwords and keys, then perform an audit to determine if they were exploited.","modified":"2022-05-25T23:09:55Z","published":"2022-05-25T23:09:55Z","database_specific":{"github_reviewed_at":"2022-05-25T23:09:55Z","nvd_published_at":null,"cwe_ids":["CWE-912"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"PACKAGE","url":"https://github.com/figlief/ctx"},{"type":"WEB","url":"https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678"},{"type":"WEB","url":"https://portswigger.net/daily-swig/malicious-python-library-ctx-removed-from-pypi-repo"},{"type":"WEB","url":"https://python-security.readthedocs.io/pypi-vuln/index-2022-05-24-ctx-domain-takeover.html"}],"affected":[{"package":{"name":"ctx","ecosystem":"PyPI","purl":"pkg:pypi/ctx"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-4g82-3jcr-q52w/GHSA-4g82-3jcr-q52w.json"}}],"schema_version":"1.9.0"}