{"id":"GHSA-5grr-72f9-678v","summary":"Malware package cipherbcrypt","details":"Malicious package. Exfiltrated secrets to a target server.","modified":"2024-07-12T21:01:13Z","published":"2024-07-12T21:01:13Z","database_specific":{"github_reviewed_at":"2024-07-12T21:01:13Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/commit/f8df7b7d0444991716fb449d55adf50067d0ba38"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cipherbcrypt/PYSEC-2024-55.yaml"}],"affected":[{"package":{"name":"cipherbcrypt","ecosystem":"PyPI","purl":"pkg:pypi/cipherbcrypt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/07/GHSA-5grr-72f9-678v/GHSA-5grr-72f9-678v.json"}}],"schema_version":"1.9.0"}