—
PYSEC-2022-250
Details
The exotel project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/exotel
Introduced in:
0.1.6No fixed version published yet for exotel (pip). Pin to a known-safe version or switch to an alternative.