{"id":"GHSA-x6xg-3fj2-4pq3","summary":"`exotel` project on PyPI compromised, malicious release made","details":"The exotel project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","modified":"2024-08-30T23:36:58Z","published":"2024-08-30T23:36:58Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-08-30T23:36:58Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/exotel/PYSEC-2022-250.yaml"},{"type":"WEB","url":"https://twitter.com/pypi/status/1562442207079976966"}],"affected":[{"package":{"name":"exotel","ecosystem":"PyPI","purl":"pkg:pypi/exotel"},"versions":["0.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-x6xg-3fj2-4pq3/GHSA-x6xg-3fj2-4pq3.json"}}],"schema_version":"1.9.0"}