Safety vulnerability ID: 49349
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Keep 1.2 included a code-execution backdoor inserted by a third party.
https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer
Latest version: 2.11
Personal shell command keeper
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. See CVE-2022-30877.
MISC:http://pypi.doubanio.com/simple/request: http://pypi.doubanio.com/simple/request
MISC:https://github.com/OrkoHunter/keep/issues/85: https://github.com/OrkoHunter/keep/issues/85
MISC:https://pypi.org/project/keep: https://pypi.org/project/keep
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application