{"id":"GHSA-5grr-72f9-678v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-5grr-72f9-678v","summary":"Malware package cipherbcrypt","details":"Malicious package. Exfiltrated secrets to a target server.","published":"2024-07-12T21:01:13Z","modified":"2024-07-12T21:01:13Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"cipherbcrypt","fixedVersion":null}],"fix":{"url":"https://github.com/pypa/advisory-database/commit/f8df7b7d0444991716fb449d55adf50067d0ba38","label":"pypa/advisory-database@f8df7b7"},"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/commit/f8df7b7d0444991716fb449d55adf50067d0ba38"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/cipherbcrypt/PYSEC-2024-55.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-07-12T21:01:13Z"}}