{"id":"GHSA-486g-47cc-8wxf","aliases":[],"url":"https://o3.security/vulnerability/GHSA-486g-47cc-8wxf","summary":"aiocpa contains credential harvesting code","details":"aiocpa is a user-facing library for generating color gradients of text. Version 0.1.13 introduced obfuscated, malicious code targeting Crypto Pay users, forwarding client credentials to a remote Telegram bot. All versions have been removed from PyPI.\n","published":"2024-11-25T22:08:57Z","modified":"2024-11-25T22:08:57Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"aiocpa","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://blog.pypi.org/posts/2024-11-25-aiocpa-attack-analysis"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/aiocpa/PYSEC-2024-152.yaml"},{"type":"WEB","url":"https://inspector.pypi.io/project/aiocpa/0.1.13/packages/ab/98/7343281068a2c39086d0b877219668a487508197f46e89b3f41046a4a8ba/aiocpa-0.1.13.tar.gz/aiocpa-0.1.13/cryptopay/utils/sync.py#line.44"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-25T22:08:57Z"}}