{"id":"GHSA-gvvw-rr8m-fj76","summary":"uniapi version 1.0.7 contained an information harvesting script.","details":"uniapi version 1.0.7 introduces code that would execute on import of the module and download a script from a remote URL, and would then execute the downloaded script in a thread. The downloaded script would harvest system information and `POST` the information to another remote URL. This code was found in the PyPI release artifacts and was not present in the public GitHub repository.","modified":"2025-02-19T19:59:23Z","published":"2025-01-27T12:30:28Z","database_specific":{"github_reviewed_at":"2025-01-27T12:30:28Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/kam193/package-campaigns/blob/main/pypi/campaigns/highly_suspicious/2025-01-uniapi.json"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/uniapi/PYSEC-2025-2.yaml"},{"type":"WEB","url":"https://inspector.pypi.io/project/uniapi/1.0.7/packages/0f/40/c6e06c22bbc22ef45f40bf5a7711763fa08fec4d16b4718d86fd60970131/uniapi-1.0.7.tar.gz/uniapi-1.0.7/uniapi/__init__.py#line.11"}],"affected":[{"package":{"name":"uniapi","ecosystem":"PyPI","purl":"pkg:pypi/uniapi"},"versions":["1.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-gvvw-rr8m-fj76/GHSA-gvvw-rr8m-fj76.json"}}],"schema_version":"1.9.0"}