Incident tracker · 24 May 2022

Are you exposed to the ctx (PyPI) takeover (May 2022)?

Attacker took over the abandoned 'ctx' package on PyPI and published versions that exfiltrate environment variables (AWS keys, tokens) on import.

Confirmed-compromised packages1 package
PyPI
ctxcompromised: 0.2.2, 0.2.6, 0.2.7, 0.2.8
Advisory / post-mortem ↗
Check your repo

CodeTrawl matches your repo’s declared dependencies against this list. Analyze a repo, then open its Security tab — an exposure to this incident shows as a dated, cited finding. Matching is manifest-scoped: it catches a compromised name@version you still declare.

Analyze a repo