{"id":"PYSEC-2022-252","details":"The deep-translator project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","modified":"2025-10-09T08:23:42.087417Z","published":"2022-08-26T17:55:00Z","references":[{"type":"ARTICLE","url":"https://twitter.com/pypi/status/1562544091719958528"}],"affected":[{"package":{"name":"deep-translator","ecosystem":"PyPI","purl":"pkg:pypi/deep-translator"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.5"}]}],"versions":["1.8.5","1.10.0","1.10.1","1.11.0","1.11.1","1.11.4","1.9.0","1.9.1","1.9.2","1.9.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/deep-translator/PYSEC-2022-252.yaml"}}],"schema_version":"1.7.3"}