{"id":"GHSA-2r6g-7r83-jg72","summary":"`spam` project on PyPI compromised, malicious releases made","details":"The `spam` project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time","modified":"2024-08-30T23:37:36Z","published":"2024-08-30T23:37:36Z","database_specific":{"github_reviewed_at":"2024-08-30T23:37:36Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/spam/PYSEC-2022-251.yaml"},{"type":"WEB","url":"https://twitter.com/pypi/status/1562442207079976966"}],"affected":[{"package":{"name":"spam","ecosystem":"PyPI","purl":"pkg:pypi/spam"},"versions":["2.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-2r6g-7r83-jg72/GHSA-2r6g-7r83-jg72.json"}},{"package":{"name":"spam","ecosystem":"PyPI","purl":"pkg:pypi/spam"},"versions":["4.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-2r6g-7r83-jg72/GHSA-2r6g-7r83-jg72.json"}}],"schema_version":"1.9.0"}