Skip to content

Conversation

github-actions[bot]
Copy link
Contributor

Automated changes by create-pull-request GitHub action

@kam193
Copy link

kam193 commented Feb 27, 2025

Hey, may I ask you to say what have you found in the Python quicly package? I looked at it a few times in the last week, but I haven't found anything suspicious besides functions to work with pickles and marshalled objects. What have I missed? Or maybe it is just a part of something bigger?

@ikretz
Copy link
Contributor

ikretz commented Feb 27, 2025

Hi @kam193, thank you for your interest in the dataset.

The affected versions of quicly overwrite the install command in the setup.py file to silently collect information about the installing system and send it to a remote server. This is a common tactic of threat actors to obtain code execution on victim systems.

@ikretz ikretz merged commit ad47729 into main Feb 27, 2025
@ikretz ikretz deleted the create-pull-request/patch-1740644984 branch February 27, 2025 11:18
@kam193
Copy link

kam193 commented Feb 27, 2025

@ikretz Right, thanks for the answer! I see it, I have mistakenly looked at the newest version instead of analyse my findings in the mentioned versions. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants