The d8s-networking package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hashes package. The affected version is 0.1.0.
Name | Vendor | Start Version | End Version |
---|---|---|---|
D8s-networking | Democritus | 0.1.0 (including) | 0.1.0 (including) |