Skip to content

code execution backdoor #36

@di1l0o

Description

@di1l0o

We discovered a potential code execution backdoor in version 0.1.0 of the project, the backdoor is the democritus-strings package. Attackers can upload democritus-strings packages containing arbitrary malicious code. For the safety of this project, the democritus-strings package has been uploaded by us.

image

The democritus-strings package can be successfully installed using pip install d8s-python==0.1.0

image

Suggestion: remove version 0.1.0 of this project in PyPI

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions