Are you exposed to the ctx (PyPI) takeover (May 2022)?
Attacker took over the abandoned 'ctx' package on PyPI and published versions that exfiltrate environment variables (AWS keys, tokens) on import.
Confirmed-compromised packages1 package
Advisory / post-mortem ↗Check your repo
CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.
Analyze a repo