CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Legacy Python Bootstrap Scripts Pose Domain-Takeover Risk in PyPI Packages

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Researchers discovered vulnerable legacy Python bootstrap scripts in multiple PyPI packages that could enable domain-takeover attacks. The scripts fetch installation files from a defunct domain (python-distribute.org), now available for purchase, potentially allowing attackers to serve malicious code. Affected packages include tornado, pypiserver, slapos.core, roman, xlutils, and testfixtures. While some packages have removed the vulnerable scripts, others like slapos.core still include them, posing a latent risk to users who might execute the scripts.

Timeline

  1. 28.11.2025 18:27 1 articles · 23h ago

    Legacy Python Bootstrap Scripts Pose Domain-Takeover Risk in PyPI Packages

    Researchers discovered vulnerable legacy Python bootstrap scripts in multiple PyPI packages that could enable domain-takeover attacks. The scripts fetch installation files from a defunct domain (python-distribute.org), now available for purchase, potentially allowing attackers to serve malicious code. Affected packages include tornado, pypiserver, slapos.core, roman, xlutils, and testfixtures. While some packages have removed the vulnerable scripts, others like slapos.core still include them, posing a latent risk to users who might execute the scripts.

    Show sources

Information Snippets