Snyk has a published code exploit for this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid usage of this package altogether.
12 Python libraries were identified as malicious packages.
smplejson
, pkgutil
, timeit
, diango
, djago
, dajngo
and mybiubiubiu
packages were vulnerable to typo-squatting attacks. These packages performed a ping back to a server indicating the package were installed.
On October 13th, 2018 all of these packages have been removed from Pypi.