{"id":"GHSA-2r6g-7r83-jg72","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2r6g-7r83-jg72","summary":"`spam` project on PyPI compromised, malicious releases made","details":"The `spam` project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","published":"2024-08-30T23:37:36Z","modified":"2024-08-30T23:37:36Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"spam","fixedVersion":null},{"ecosystem":"PyPI","name":"spam","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/spam/PYSEC-2022-251.yaml"},{"type":"WEB","url":"https://twitter.com/pypi/status/1562442207079976966"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-30T23:37:36Z"}}