Skip to content

Comment on Investigating a backdoored PyPI package targeting FastAPI applicationsparent

Comments

In order to be a bit more constructive, what is the ideal process for the author to remove it?

The issue in general of backdoored packages is not new, but that it happened to you can be a new issue if you haven't either thought of it before or not simply encountered before. It would be very helpful if there was a resource out there answering the question "So your package was backdoored, what do you do now?" that people could refer to and get help.

Some kind of post-mortem or statement at all about how the GitHub account got compromised, if that's what happened here.

It could have also been a researcher checking to see if anyone would notice, or something worse.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.