Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise
ID: 95f9b319-38bc-507d-9000-6a0c879790f1
STIX ID: report--95f9b319-38bc-507d-9000-6a0c879790f1
Feed Name: cybersecurityNews.com
The report outlines a supply-chain vulnerability in legacy zc.buildout bootstrap scripts that hardcode fetching the now-defunct python-distribute.org; responses from that domain are passed directly to exec() with no integrity checks. ReversingLabs identified affected packages (including slapos.core, pypiserver, and tornado) and demonstrated a proof-of-concept that forces the vulnerable download path, highlighting a domain-takeover vector that could execute arbitrary code when developers run outdated bootstrap scripts or build steps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
