MITB Banner

Widely used Python and PHP libraries compromised

PyPI took down the malicious ctx versions soon, however, reports still indicate the presence of malicious code within all ctx versions.
Share
PHP attack

In a software supply chain attack, PyPI module ctx has been compromised. By this attack, the safer version of this module (which is downloaded 20,000 times a week) was replaced with code that exfiltrates the developer’s environment variables to collect secret codes like Amazon AWS keys. 

‘Ctx’ is a minimal Python module that lets developers manipulate dictionary ‘dict’ objects in a number of ways. Interestingly, after remaining untouched for 8 years, newer versions started emerging on May 15 and contained malicious code. PyPI took down the malicious ctx versions soon, however, reports still indicate the presence of malicious code within all ctx versions.

Further, the attacker versions of PHPass fork, which are published to the PHP/Composer package repository Packagist, were altered to steal confidential keys and credentials. PHPass is an open-source password hashing framework that can be used in PHP applications. Released in 2005, the framework has been downloaded over 2.5 million times on Packagist. As per reports, malicious commits were made to PHPass project this week to steal environment variables.

The presence of identical logic and Heroku endpoints within the PyPI and PHP packages indicate a common threat actor being responsible for both of these hijacks. While there are few suspicions around the identity of the attackers, experts are not ruling out the possibility of a PoC exercise gone wrong.

PS: The story was written using a keyboard.
Share
Picture of Shraddha Goled

Shraddha Goled

I am a technology journalist with AIM. I write stories focused on the AI landscape in India and around the world with a special interest in analysing its long term impact on individuals and societies. Reach out to me at shraddha.goled@analyticsindiamag.com.
Related Posts

CORPORATE TRAINING PROGRAMS ON GENERATIVE AI

Generative AI Skilling for Enterprises

Our customized corporate training program on Generative AI provides a unique opportunity to empower, retain, and advance your talent.

Upcoming Large format Conference

May 30 and 31, 2024 | 📍 Bangalore, India

Download the easiest way to
stay informed

Subscribe to The Belamy: Our Weekly Newsletter

Biggest AI stories, delivered to your inbox every week.

AI Courses & Careers

Become a Certified Generative AI Engineer

AI Forum for India

Our Discord Community for AI Ecosystem, In collaboration with NVIDIA. 

Flagship Events

Rising 2024 | DE&I in Tech Summit

April 4 and 5, 2024 | 📍 Hilton Convention Center, Manyata Tech Park, Bangalore

MachineCon GCC Summit 2024

June 28 2024 | 📍Bangalore, India

MachineCon USA 2024

26 July 2024 | 583 Park Avenue, New York

Cypher India 2024

September 25-27, 2024 | 📍Bangalore, India

Cypher USA 2024

Nov 21-22 2024 | 📍Santa Clara Convention Center, California, USA

Data Engineering Summit 2024

May 30 and 31, 2024 | 📍 Bangalore, India