Security News > 2024 > August > Leaked GitHub Python Token

Leaked GitHub Python Token
2024-08-02 11:01

Cybersecurity researchers from JFrog recently discovered a GitHub Personal Access Token in a public Docker container hosted on Docker Hub, which granted elevated access to the GitHub repositories of the Python language, Python Package Index, and the Python Software Foundation.

The implications of someone finding this leaked token could be extremely severe.

The holder of such a token would have had administrator access to all of Python's, PyPI's and Python Software Foundation's repositories, supposedly making it possible to carry out an extremely large scale supply chain attack.

Various forms of supply chain attacks were possible in this scenario.

One such possible attack would be hiding malicious code in CPython, which is a repository of some of the basic libraries which stand at the core of the Python programming language and are compiled from C code.

Due to the popularity of Python, inserting malicious code that would eventually end up in Python's distributables could mean spreading your backdoor to tens of millions of machines worldwide!


News URL

https://www.schneier.com/blog/archives/2024/08/leaked-github-python-token.html

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Python 27 10 87 75 27 199
Github 13 3 43 30 17 93