democritus-project/d8s-urls

code execution backdoor

di1l0o opened this issue · 0 comments

We discovered a potential code execution backdoor in version 0.1.0 of the project, the backdoor is the democritus-networking package. Attackers can upload democritus-networking packages containing arbitrary malicious code. For the safety of this project, the democritus-networking package has been uploaded by us.

image

The democritus-networking package can be successfully installed using pip install d8s-urls==0.1.0

image

Suggestion: remove version 0.1.0 of this project in PyPI