{"id":"PYSEC-2022-251","details":"The spam project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","modified":"2022-08-26T17:55:00Z","published":"2022-08-26T17:55:00Z","references":[{"type":"ARTICLE","url":"https://twitter.com/pypi/status/1562442207079976966"}],"affected":[{"package":{"name":"spam","ecosystem":"PyPI","purl":"pkg:pypi/spam"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.2"}]}],"versions":["2.0.2","4.0.2"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/spam/PYSEC-2022-251.yaml"}}],"schema_version":"1.7.3"}