Account Takeover 2022 Incident #10

ctx package (PyPI)

Estimated Financial Impact
27K malicious downloads
Blast Radius
AWS credential theft via expired domain

What Happened

An attacker purchased the expired domain associated with the original maintainer's email for $5, used PyPI's password reset flow to take over the account, and replaced all versions with code that exfiltrated environment variables (including AWS keys) to a Heroku endpoint. Roughly 27,000 malicious downloads occurred, collecting ~1,000 sets of environment variables.

✓

Risk Guard: Caught

PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install

Risk Guard Check Codes That Flag This Incident

PACKAGE_ACTIVE_MALWAREPACKAGE_STALE_RELEASESOURCE_SINGLE_CONTRIBUTOR

How Every Tool Performed

2 Caught 0 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught PACKAGE_STALE_RELEASE + SOURCE_SINGLE_CONTRIBUTOR flagged as abandoned before takeover; PACKAGE_ACTIVE_MALWARE at install
Socket Caught Behavioral analysis detects exfiltration
Snyk Missed No malware detection
Sonatype (Nexus) Missed Weak PyPI/RubyGems coverage for dormant packages
Black Duck Missed No malware detection
Endor Labs Missed No malware detection
← Rspack and Vant strong_password gem →