GHSA-x6xg-3fj2-4pq3: `exotel` project on PyPI compromised, malicious release made
The exotel project on PyPI was taken over via user account compromise via a phishing attack and a new malicious release made which contained code which some environment variables and downloaded and ran malware at install time
References
Detect and mitigate GHSA-x6xg-3fj2-4pq3 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →