BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Legacy Python Package Vulnerabilities Risk Supply Chain Attacks via Domain Takeover

Legacy Python Packages Vulnerable to Domain Takeover Attacks via Outdated Bootstrap Scripts on PyPI

  • Legacy Python packages contain vulnerable bootstrap scripts that can enable domain takeover attacks on PyPI.
  • The vulnerable bootstrap scripts fetch installation files from a now-available domain used by the obsolete Distribute package.
  • Attackers could exploit the unclaimed domain to deliver malicious code via these scripts when executed.
  • The bootstrap script is embedded in several popular packages, including Tornado and slapos.core, posing an ongoing risk.
  • A separate malicious PyPI package named “spellcheckers” deployed a remote access trojan, demonstrating current threats to the Python ecosystem.

Cybersecurity researchers have identified security risks in older Python packages distributed through the Python Package Index (PyPI) due to vulnerable bootstrap scripts. These scripts load installation files from a defunct domain, exposing projects to potential supply chain attacks.

- Advertisement -

The issue centers on the bootstrap script associated with the build and deployment automation tool zc.buildout. This script attempts to download the installation script for the now-obsolete packaging utility Distribute from python-distribute[.]org. This domain has been available for purchase since 2014 and currently generates ad revenue. Security researcher Vladimir Pezo explained that the script fetches and installs Distribute by default or when specific command-line options are used, which creates an attack vector if the domain is acquired by malicious actors, as noted on the ReversingLabs blog.

Multiple PyPI packages, including tornado, pypiserver, slapos.core, roman, xlutils, and testfixtures, still contain the vulnerable bootstrap script. Though the script is written in Python 2 and not automatically executed during package installation, its presence offers an unnecessary attack surface that could be exploited if developers run it manually. Some affected packages have removed the script, but slapos.core and the development version of Tornado continue to include it.

This vulnerability is reminiscent of a 2023 incident with the npm package fsevents, where attackers took control over an unclaimed cloud resource to distribute malicious payloads, referenced in CVE-2023-45311.

In a separate security incident, the company HelixGuard discovered a malicious PyPI package named “spellcheckers.” This package claimed to provide spelling error detection using OpenAI Vision but in reality, installed a remote access trojan (RAT). The trojan connects to an external server to download and execute harmful code, allowing attackers to run arbitrary Python commands remotely. The package was first uploaded on November 15, 2025, by the user leo636722 and had been downloaded 955 times before removal. HelixGuard detailed the threat on their official blog.

- Advertisement -

“The issue lies in the programming pattern that includes fetching and executing a payload from a hard-coded domain, which is a pattern commonly observed in Malware exhibiting downloader behavior,” Pezo said, highlighting the risks of leaving outdated scripts in active use.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Analyst: Bitcoin’s $100K Push Needs No New Narrative

Analyst Michael van de Poppe suggests Bitcoin’s price can rise to $100,000 without a...

US Crypto CLARITY Act Advances With Stablecoin Rule Text

The CLARITY Act, which aims to provide regulatory clarity for crypto, moves closer to...

Bitcoin Targets $80K As Data Signals Strong Buy Pressure

Bitcoin's price rebounded 2.52% to above $78,800 on Friday, holding support at its 100-day...

Google AppSheet Phishing Wave Hits 30K Facebook Accounts

Vietnamese threat actors used Google AppSheet as a phishing relay to compromise roughly 30,000...

Trump to hike EU auto tariffs to 25% from next week

Former US President Donald Trump announced via social media that tariffs on European Union...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading