Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparentComments−agolio3yFully agree, worth re-iterating as the title doesn't make it clear.The vulnerability is not in FastAPI itself, but in a relatively unknown utility package that you probably aren't using.Still good to raise awareness but a slight bit of scaremongering−christophetd3yHello! One of the authors of the post here. Just added a sentence in the introduction to make it crystal clear:While FastAPI itself is not impacted, this is an interesting occurrence of an attacker attempting to deploy a FastAPI-specific backdoor.Appreciate your feedback!−flutas3yFYI: You left a name and email in the github history.I know they are public via GH, but it feels weird to redact every piece of PII including avatar, then leaving a name and email in there.−christophetd3yThanks for the heads-up, the goal was mostly avoiding that typing the author's name in Google brings up this post. I'll have it blurred for the sake of consistency, though.−capableweb3yStill good to raise awareness but a slight bit of scaremongeringIt's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech:using our latest open source tool, GuardDog, which uses heuristics to identify malicious or compromised PyPI packages.We recently released GuardDog, a free and open-source tool to identify malicious PyPI packagesDatadog ASM Vulnerability Monitoring, announced earlier this year at Dash, allows you to identify vulnerable and malicious packagesDatadog Cloud Workload Security has a number of out-of-the-box rules to detect post exploitation scenarios
Comments
Fully agree, worth re-iterating as the title doesn't make it clear.
The vulnerability is not in FastAPI itself, but in a relatively unknown utility package that you probably aren't using.
Still good to raise awareness but a slight bit of scaremongering
Hello! One of the authors of the post here. Just added a sentence in the introduction to make it crystal clear:
Appreciate your feedback!
FYI: You left a name and email in the github history.
I know they are public via GH, but it feels weird to redact every piece of PII including avatar, then leaving a name and email in there.
Thanks for the heads-up, the goal was mostly avoiding that typing the author's name in Google brings up this post. I'll have it blurred for the sake of consistency, though.
It's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech: