8 ms·
The regex they have for identifying fake/harmful packages is wrong. `pip list –format=legacy | egrep '^(acqusition|apidev-coop|bzip|crypt|django-server|pwd|set
by rantanplan 9y ago
The regex they have for identifying fake/harmful packages is wrong.
`pip list –format=legacy | egrep '^(acqusition|apidev-coop|bzip|crypt|django-server|pwd|setup-tools|telnet|urlib3|urllib) '`
This incorrectly lists `urllib3` or the `cryptography` package for example, which are perfectly valid packages.
[UPDATE]
Read "tobltobs" comment below. I incorrectly removed a trailing space from the regex.
- nariinano 9y agoI believe urllib3 is built-in. So if you have installed it from PyPI you've gotten a malicious version.
- rantanplan 9y agohttps://pypi.python.org/pypi/urllib3 https://pypi.python.org/pypi/urllib3
- cpburns2009 9y agourllib and urllib2 are built-in for Python 2, and were merged and reorganized as just urllib in Python 3. urllib3 is a third-party module.
- haikuginger 9y agoThis is correct. In general, though, most packages don't rely on urllib3 directly, but on `requests`, which uses urllib3 but provides a friendlier API and built-in SSL cert verification.
- wyldfire 9y agoIt's not generally true that built-in packages which also appear on PyPI are malicious. Many batteries-included packages are also maintained outside of CPython. This is because: (1) in many cases they existed outside prior to being included in CPython, (2) they can experiment with new features before they're included in the CPython version of their package.
- deleted 9y ago[deleted]
- tobltobs 9y agoNot for me. There is space at the end between the closing bracket and the apostrophe. Maybe you did remove this space when you corrected the smart apostrophes.
- rantanplan 9y agoYou're right. It seems I did remove the space. When I put it back in it doesn't print anything.
- julianj 9y agoxml should be added to this list. https://pypkg.com/pypi/xml/f/setup.py https://pypkg.com/pypi/xml/f/setup.py
- osteele 9y agoConda users: Here's a script that runs this check against each environment: https://gist.github.com/osteele/198b50a2a208e5bc7e5fb8d010cf590c https://gist.github.com/osteele/198b50a2a208e5bc7e5fb8d010cf...
- jastr 9y agopip list --format=legacy | cut -d' ' -f1 | xargs egrep '^(acqusition|apidev-coop|bzip|crypt|django-server|pwd|setup-tools|telnet|urlib3|urllib)$'
- pmoriarty 9y agoWhen running that command, I get output like this: grep: alabaster: No such file or directory grep: appdirs: No such file or directory grep: arandr: No such file or directory for dozens and dozens of packages. Are those errors benign?