aiocpa contains credential harvesting code
High severity
GitHub Reviewed
Published
Nov 25, 2024
to the GitHub Advisory Database
•
Updated Nov 25, 2024
Description
Published to the GitHub Advisory Database
Nov 25, 2024
Reviewed
Nov 25, 2024
Last updated
Nov 25, 2024
aiocpa is a user-facing library for generating color gradients of text. Version 0.1.13 introduced obfuscated, malicious code targeting Crypto Pay users, forwarding client credentials to a remote Telegram bot. All versions have been removed from PyPI.
References