6 ms·
Related to this? http://incolumitas.com/2016/06/08/typosquatting-package-managers/ http://incolumitas.com/2016/06/08/typosquatting-package-mana...
by sdiepend 9y ago
Related to this? http://incolumitas.com/2016/06/08/typosquatting-package-managers/ http://incolumitas.com/2016/06/08/typosquatting-package-mana...
- xnyhps 9y agoThat one is even more malicious, it uploads contents of your ~/.bash_history and system profile. But at least it notifies you afterwards...
- edraferi 9y agoYes, but they do filter bash_history client side, only transmitting pip-related commands. They did this to find additional common typos. The relevant code: def get_command_history(): if os.name == 'nt': # handle windows # http://serverfault.com/questions/95404/ #is-there-a-global-persistent-cmd-history # apparently, there is no history in windows :( return '' elif os.name == 'posix': # handle linux and mac cmd = 'cat {}/.bash_history | grep -E "pip[23]? install"' return os.popen(cmd.format(os.path.expanduser('~'))).read()