VDB
Sign up
HIGH

GHSA-2r6g-7r83-jg72

`spam` project on PyPI compromised, malicious releases made

Details

The `spam` project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/spam

No fixed version published yet for spam (pip). Pin to a known-safe version or switch to an alternative.

PyPI/spam

No fixed version published yet for spam (pip). Pin to a known-safe version or switch to an alternative.

References