Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

SC-CTX-PHPASS-2022

PyPI · ctx / phpass

Résumé

In May 2022 the PyPI package 'ctx' (around 20,000 downloads per week) was hijacked after its maintainer's domain name expired; the attacker re-registered the domain on May 14, 2022, performed a password reset on the maintainer's account, and replaced both new and existing versions with backdoored ones. A forked PHP project, 'phpass', was hit with an identical payload via repo hijacking. The malicious code harvested all environment variables, base64-encoded them and exfiltrated them (targeting AWS keys and credentials) to a Heroku endpoint, anti-theft-web.herokuapp.com.

Références

Vulnérabilités liées

Tout Supply chain →