The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Link | Tags |
---|---|
http://pypi.doubanio.com/simple/request | not applicable |
https://pypi.org/project/bin-collect/ | release notes product |
https://github.com/Gmiller290488/bin_collection/issues/1 | third party advisory |