Skip to content

Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparent

Comments

Fully agree, worth re-iterating as the title doesn't make it clear.

The vulnerability is not in FastAPI itself, but in a relatively unknown utility package that you probably aren't using.

Still good to raise awareness but a slight bit of scaremongering

Hello! One of the authors of the post here. Just added a sentence in the introduction to make it crystal clear:

While FastAPI itself is not impacted, this is an interesting occurrence of an attacker attempting to deploy a FastAPI-specific backdoor.

Appreciate your feedback!

FYI: You left a name and email in the github history.

I know they are public via GH, but it feels weird to redact every piece of PII including avatar, then leaving a name and email in there.

Thanks for the heads-up, the goal was mostly avoiding that typing the author's name in Google brings up this post. I'll have it blurred for the sake of consistency, though.

Still good to raise awareness but a slight bit of scaremongering

It's not scaremongering as much as it is a (thinly veiled) ad for Datadog's own tech:

using our latest open source tool, GuardDog, which uses heuristics to identify malicious or compromised PyPI packages.
We recently released GuardDog, a free and open-source tool to identify malicious PyPI packages
Datadog ASM Vulnerability Monitoring, announced earlier this year at Dash, allows you to identify vulnerable and malicious packages
Datadog Cloud Workload Security has a number of out-of-the-box rules to detect post exploitation scenarios
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.