{"id":"GHSA-x6xg-3fj2-4pq3","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x6xg-3fj2-4pq3","summary":"`exotel` project on PyPI compromised, malicious release made","details":"The exotel project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","published":"2024-08-30T23:36:58Z","modified":"2024-08-30T23:36:58Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"exotel","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/exotel/PYSEC-2022-250.yaml"},{"type":"WEB","url":"https://twitter.com/pypi/status/1562442207079976966"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-30T23:36:58Z"}}