https://www.reddit.com/r/Python/comments/uwhzkj/i_think_the_ctx_package_on_pypi_has_been_hacked
Someone bought the defunct domain of the account used to publish a popular library (which hasn't seen updates), and used it to gain access to the PyPI account and publish a new, malicious, version.
(Uploading all env vars to a domain on dict construction, which IMO is so eager it's bound to get caught)
h
high-yak-85899
06/06/2022, 4:18 PM
Yeah, we did a scrub of our repos for this when it came out. Should have shared here 🤦