Loading article…

PyPI “ctx” saw a malicious version uploaded on May 14 2022, targeting 22,000 weekly downloads to exfiltrate AWS keys—learn how the takeover happened and what
A malicious version of the Python package ctx appeared on PyPI on May 14 2022, inserting code that harvests AWS credentials and other environment variables and ships them to a attacker‑controlled server [2].
The attack hinged on the original maintainer’s domain expiring; the threat actor registered the domain on the same day and used the new email address to reset the maintainer’s password and push three rogue releases (0.1.2, 0.2.2, 0.2.6) [2]. The injected payload captures the AWS access key ID, secret key, and computer name, or in another variant, all environment variables, encoding them in Base64 before sending them to a Heroku URL [1].
Both the SANS Internet Storm Center and Sonatype traced the incident to a broader pattern of supply‑chain hijacks, noting that the “ctx” package had not been updated since December 2014 before the malicious upload, and that similar tactics have been used to hijack thousands of NPM packages via expired maintainer domains [1]. An Istanbul‑based researcher later claimed responsibility, saying he bought the expired domain for $5 and used the password‑reset flow to gain control, framing the act as a demonstration of the risk to over ten million users [1].
The compromised versions have since been removed from PyPI, but the episode underscores how stale packages and neglected domain registrations can become entry points for attackers. Developers who installed any “ctx” release after May 14 should verify they are not running the malicious code and consider regenerating any AWS keys that may have been exposed.
The incident raises a lingering question: as open‑source ecosystems continue to grow, how can maintainers and repository operators better safeguard abandoned packages and domains to prevent similar supply‑chain breaches?
Coverage is mostly measured — 210 of 263 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
Openai is a trending topic in the news. Recent coverage of Openai includes: Powerful A.
10 news sources analyzed
Based on our analysis of recent news articles, Openai has mixed coverage. Check the sentiment score above for detailed analysis.
TrendWatcher aggregates Openai news from 100+ trusted sources and provides AI-powered sentiment analysis updated in real-time.
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Jun 13, 2026 · How we report