<https://www.reddit.com/r/Python/comments/uwhzkj/i...
# random
b
https://www.reddit.com/r/Python/comments/uwhzkj/i_think_the_ctx_package_on_pypi_has_been_hacked Someone bought the defunct domain of the account used to publish a popular library (which hasn't seen updates), and used it to gain access to the PyPI account and publish a new, malicious, version. (Uploading all env vars to a domain on dict construction, which IMO is so eager it's bound to get caught)
h
Yeah, we did a scrub of our repos for this when it came out. Should have shared here 🤦