-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
Hello!
This unmet dependency on library roslib (https://pypi.org/project/roslib/) may be registered in pypi by intruder.
This way intruder can:
- register
roslibon pypi to execute malicious code intopic-store(at least in versions0.1.8and0.1.7). - register
rosliband addtopic_storeas a dependency of opensource package.topic_storelibrary seems to be useful for manipulating with ROS messages, this way it won't be unusial to use it. - register
roslib+ non-malicious typosquatted library (e.g.eequests) which will depends ontopic_store- looks like good supply chain attack)
Metadata
Metadata
Assignees
Labels
No labels