You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I'm a Cyber Security researcher and developer of PackjGuard [1] to address open-source software supply chain attacks.
Issue
During my research, I detected a deleted package in this repository.
Details
Specifically, the package owndc mentioned in file README at line 39 does not exist on the public PyPI registry. A bad actor can hijack this package to propagate malicious code.
Impact
Not only your apps/services using https://github.com/javiquinte/owndc repo code are vulnerable to this attack, but the users of your open-source Github repo could also fall victim.
Please highlight this in file README and register a placeholder package for owndc on public PyPI soon to remediate.
To automatically fix such issues in future, please install PackjGuard Github app [1].
Thanks!
PackjGuard is a Github app that monitors your repos 24x7, detects vulnerable/malicious/risky open-source dependencies, and creates pull requests for auto remediation: https://github.com/marketplace/packjguard
The text was updated successfully, but these errors were encountered:
I'm a Cyber Security researcher and developer of PackjGuard [1] to address open-source software supply chain attacks.
Issue
During my research, I detected a deleted package in this repository.
Details
Specifically, the package
owndc
mentioned in fileREADME
at line 39 does not exist on the public PyPI registry. A bad actor can hijack this package to propagate malicious code.Impact
Not only your apps/services using
https://github.com/javiquinte/owndc
repo code are vulnerable to this attack, but the users of your open-source Github repo could also fall victim.You could read more about such attacks here: https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610
Remediation
Please highlight this in file README and register a placeholder package for
owndc
on public PyPI soon to remediate.To automatically fix such issues in future, please install PackjGuard Github app [1].
Thanks!
The text was updated successfully, but these errors were encountered: