{"id":"PYSEC-2025-2","summary":"uniapi version 1.0.7 contained an information harvesting script.","details":"uniapi version 1.0.7 introduces code that would execute\non import of the module and download a script from a remote URL,\nand would then execute the downloaded script in a thread.\nThe downloaded script would harvest system information\nand `POST` the information to another remote URL.\nThis code was found in the PyPI release artifacts and was not present\nin the public GitHub repository.\n","modified":"2025-01-24T19:56:53Z","published":"2025-01-24T19:56:53Z","references":[{"type":"EVIDENCE","url":"https://inspector.pypi.io/project/uniapi/1.0.7/packages/0f/40/c6e06c22bbc22ef45f40bf5a7711763fa08fec4d16b4718d86fd60970131/uniapi-1.0.7.tar.gz/uniapi-1.0.7/uniapi/__init__.py#line.11"},{"type":"WEB","url":"https://github.com/kam193/package-campaigns/blob/main/pypi/campaigns/highly_suspicious/2025-01-uniapi.json"}],"affected":[{"package":{"name":"uniapi","ecosystem":"PyPI","purl":"pkg:pypi/uniapi"},"versions":["1.0.7"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/uniapi/PYSEC-2025-2.yaml"}}],"schema_version":"1.7.5","credits":[{"name":"Mike Fiedler","type":"COORDINATOR"},{"name":"Kamil Mańkowski","type":"REPORTER"}]}