{"id":23882,"date":"2021-03-01T12:09:29","date_gmt":"2021-03-01T17:09:29","guid":{"rendered":"https:\/\/www.rc.fas.harvard.edu\/?p=23882"},"modified":"2021-03-01T12:09:29","modified_gmt":"2021-03-01T17:09:29","slug":"security-advisory-03012021","status":"publish","type":"post","link":"https:\/\/www.rc.fas.harvard.edu\/blog\/security-advisory-03012021\/","title":{"rendered":"Security advisory regarding Python\/Conda\/pip\/PyPI"},"content":{"rendered":"<p><strong>AUDIENCE<\/strong>: All Python\/Conda users<\/p>\n<p><strong>IMPACT<\/strong>: Potential malicious packages installed or malware downloaded<\/p>\n<p>Numerous packages containing malware\/malicious links have been uploaded to the PyPI (Python Package Index) repository. Many of these have names which are slight misspellings of the names of other packages. The intention is to cause an installation of one of these packages if the package name is mistyped during installation by a user. <\/p>\n<p>Please be aware that this sort of \u2018supply chain\u2019 attack is always possible with these sorts of open repositories. Anyone can add to them and there is no centralized vetting or curation of packages.<\/p>\n<p>Please always double-check the name of any package before installing into your environment or on your local machine. This advice applies to all software and repositories, but with particular current scrutiny on the PyPI repository and cupy packages. Always ensure software you are installing is from a credible, trusted source and that the URL or package name is correct.<\/p>\n<p>If you believe you have installed a malicious package, please contact us ASAP at:<br \/>\n<a href=\"mailto:rchelp@rc.fas.harvard.edu\" target=\"_blank\" rel=\"noopener\">rchelp@rc.fas.harvard.edu<\/a><\/p>\n<p>Additional details\/links:<br \/>\nSearch PyPI projects: <a href=\"https:\/\/pypi.org\/\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/pypi.org\/&amp;source=gmail&amp;ust=1614701413686000&amp;usg=AFQjCNE5mTR7TAhYKU4OihGBNUH6jOeHYA\">https:\/\/pypi.org\/<\/a><br \/>\n<a href=\"https:\/\/github.com\/pypa\/pypi-support\/issues\/923\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/github.com\/pypa\/pypi-support\/issues\/923&amp;source=gmail&amp;ust=1614701413686000&amp;usg=AFQjCNGttKTbCcrNy192aGjIl8bnlwQs4w\">https:\/\/github.com\/pypa\/pypi-<wbr \/>support\/issues\/923<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"lead\">AUDIENCE: All Python\/Conda users IMPACT: Potential malicious packages installed or malware downloaded Numerous packages containing malware\/malicious links have been uploaded to the PyPI (Python Package Index) repository. Many of these have names which are slight misspellings of the names of other packages. The intention is to cause an installation of one of these packages if the package name is mistyped&hellip;<\/p>\n<p class=\"more-link-p\"><a class=\"btn btn-primary\" href=\"https:\/\/www.rc.fas.harvard.edu\/blog\/security-advisory-03012021\/\">Read more<\/a><\/p>\n","protected":false},"author":111,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[36],"tags":[193],"class_list":["post-23882","post","type-post","status-publish","format-standard","hentry","category-blog","tag-security"],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p42YvN-6dc","jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/posts\/23882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/users\/111"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/comments?post=23882"}],"version-history":[{"count":2,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/posts\/23882\/revisions"}],"predecessor-version":[{"id":23884,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/posts\/23882\/revisions\/23884"}],"wp:attachment":[{"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/media?parent=23882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/categories?post=23882"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rc.fas.harvard.edu\/wp-json\/wp\/v2\/tags?post=23882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}