VDB
Sign up
CRITICAL

GHSA-67r3-h899-9w95

Embedded Malicious Code in ctx

Details

The ctx hosted project on PyPI was taken over via user account compromise and replaced with a malicious project which contained runtime code which collected the content of os.environ.items() when instantiating Ctx objects.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ctx
Introduced in: 0.1.2-1

No fixed version published yet for ctx (pip). Pin to a known-safe version or switch to an alternative.

References