Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsAvoid using all malicious instances of the mrmustard package.
mrmustard is a malicious package. This package contains malicious code, and its content was quarantined by the official package manager. Version 0.7.4 was published to PyPI using stolen maintainer credentials and contained an injected credential stealer. The malicious code ran upon import to harvest SSH keys, AWS credentials, Kubernetes configurations, and HPC cluster details, sending them to an external command-and-control server. The malicious payload existed exclusively in the PyPI artifact and was not present in the legitimate XanaduAI source repository. Earlier versions are safe.