{"id":"GHSA-4g82-3jcr-q52w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4g82-3jcr-q52w","summary":"Malware in ctx","details":"The `ctx` hosted project on [PyPI](https://pypi.org/project/ctx/) was taken over via user account compromise and replaced with a malicious project which contained runtime code that collected the content of `os.environ.items()` when instantiating `Ctx` objects. The captured environment variables were sent as a base64 encoded query parameter to a heroku application running at `https://anti-theft-web.herokuapp.com`.\n\nIf you installed the package between May 14, 2022 and May 24, 2022, and your environment variables contain sensitive data like passwords and API keys (like `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY`), we advise you to rotate your passwords and keys, then perform an audit to determine if they were exploited.","published":"2022-05-25T23:09:55Z","modified":"2022-05-25T23:09:55Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"ctx","fixedVersion":null}],"fix":null,"references":[{"type":"PACKAGE","url":"https://github.com/figlief/ctx"},{"type":"WEB","url":"https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678"},{"type":"WEB","url":"https://portswigger.net/daily-swig/malicious-python-library-ctx-removed-from-pypi-repo"},{"type":"WEB","url":"https://python-security.readthedocs.io/pypi-vuln/index-2022-05-24-ctx-domain-takeover.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-05-25T23:09:55Z"}}