A GitHub token leak could have put the entire Python language at risk
What if the Python programming language itself was malicious? It would be the most devastating supply chain attack in human history – but it almost happened after an important GitHub token was accidentally leaked.
Cybersecurity researchers from JFrog recently discovered a GitHub Personal Access Token in a public Docker container hosted on Docker Hub, which granted elevated access to the GitHub repositories of the Python language, Python Package Index (PyPI), and the Python Software Foundation (PSF).
“This case was exceptional because it is difficult to overestimate the potential consequences if it had fallen into the wrong hands – one could supposedly inject malicious code into PyPI packages (imagine replacing all Python packages with malicious ones), and even to the Python language itself,” the researchers said in their writeup.
Exposed for months
They added that they found the token inside a Docker container in a compiled Python file that was erroneously not cleaned up.
According to PyPI, the token was issued before March 3, 2023, but the exact date is impossible to determine since the logs only last for 90 days. PyPI Admin Ee Durbin was notified on June 28 this year, after which the token was revoked.
The Python package Index (PyPI), is the world’s number one source for Python packages. The open-source platform is a central hub for developers looking to publish and share their Python software and libraries with the community. As such, it is an extremely popular target for cybercriminals interested in supply-chain attacks. By sneaking malicious packages into the platform (or poisoning existing ones), cybercriminals can compromise hundreds of organizations in one fell swoop.
To make matters worse, many Fortune 100 companies use PyPI in their software products, including Google, Microsoft, Amazon, and Apple.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
In late March 2024, the platform was forced to suspend new account and new project registrations to tackle a large-scale cyberattack in which threat actors tried to upload hundreds of malicious packages.
Via TheHackerNews
More from TechRadar Pro
What if the Python programming language itself was malicious? It would be the most devastating supply chain attack in human history – but it almost happened after an important GitHub token was accidentally leaked. Cybersecurity researchers from JFrog recently discovered a GitHub Personal Access Token in a public Docker container…
Recent Posts
- The Dyson HushJet Mini Cool is the powerful personal fan you won’t want to live without this summer — and it’s surprisingly reasonably priced, too
- Gone in 60 minutes
- GroWell Cap Review: I Have Hair for the First Time in 15 Years
- The Sonos Era 100 speaker is down to its lowest price in months
- Google shuts down the AI image app Pixel Studio
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023