logo

Vulnerable Codes in Legacy Python Packages Enables Attacks on Python Package Index Via Domain Compromise

ID: 95f9b319-38bc-507d-9000-6a0c879790f1

STIX ID: report--95f9b319-38bc-507d-9000-6a0c879790f1

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

The report outlines a supply-chain vulnerability in legacy zc.buildout bootstrap scripts that hardcode fetching the now-defunct python-distribute.org; responses from that domain are passed directly to exec() with no integrity checks. ReversingLabs identified affected packages (including slapos.core, pypiserver, and tornado) and demonstrated a proof-of-concept that forces the vulnerable download path, highlighting a domain-takeover vector that could execute arbitrary code when developers run outdated bootstrap scripts or build steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.