The ctx PyPI and phpass Supply Chain Attack
Updated 5 Oct 2026 · Incident date 21 May 2022 · PyPI
ctx 0.1.2 (2014, clean) -> republished 0.1.2 plus 0.2.2 and 0.2.6; hautelook/phpass on Packagist likewisectx/__init__.pyIn May 2022, an attacker hijacked the Python package ctx on PyPI and the PHP package hautelook/phpass. The bad ctx releases were 0.1.2 (republished), 0.2.2 and 0.2.6. Both packages sent the host's environment variables to the attacker.
The last real ctx release was in December 2014, so the new releases looked like a revival of an old package.
What happened
The attacker took over two long-idle packages and added code that stole environment variables. The Hacker News reports that the attacker bought the expired domain figlief[.]com, which was tied to the ctx maintainer's account, on 14 May 2022. The attacker then used the password reset to take the PyPI account. Checkmarx dates the account takeover to 15 May and the malicious ctx versions to 21 May 2022.
The phpass case used a different method called repo hijacking. Checkmarx reports that the original hautelook GitHub account was closed in September 2021. The attacker registered the same account name on 15 May 2022 and added malicious commits on 19 May. PHP projects take dependencies straight from source control, so this reached users. Detection came on 24 May 2022.
The code collected all environment variables, encoded them in Base64 and sent them to anti-theft-web.herokuapp[.]com. It aimed at AWS credentials. In phpass it kept the original function working as cover.
The attacker, an Istanbul-based researcher named in The Hacker News, said the goal was to show a weakness in supply chains. The effect was still credential theft from real users.
Vigilance compares the version you trust with the new one. A republished ctx 0.1.2 that now reads the environment and sends it out is the kind of change it reports as a new capability. See the scan block below.
Affected versions
ctxon PyPI: 0.1.2 (the old release was replaced with tainted code), 0.2.2 and 0.2.6. Sonatype says later versions also held the code.hautelook/phpasson Packagist, in the same time window. The Hacker News describes the PHP package as a Packagist fork with few installs.- Checkmarx also names
optimistdigital/nova-tailwindas hit by the same attacker through a recreated GitHub name.
The last real ctx release was 0.1.2 on 19 December 2014. The last real phpass update was 31 August 2012. PyPI and GitHub removed the bad code.
Indicators of compromise
- Exfiltration host:
anti-theft-web.herokuapp[.]com, and the path/hacked/reported by Sonatype. - ctx versions 0.2.2 or 0.2.6, or a 0.1.2 that was installed after 21 May 2022.
- Domain tied to the hijacked account:
figlief[.]com. - Sonatype tracking ID:
sonatype-2022-3060.
How to check
Check whether ctx is installed and which version.
pip show ctx
Search code and logs for the exfiltration host.
grep -rn "anti-theft-web" . $(python3 -c "import site;print(site.getsitepackages()[0])") 2>/dev/null
For PHP, check the lock file with grep -n "hautelook/phpass" composer.lock and read the commit hash. Also check proxy logs for traffic to herokuapp.com from build and application hosts.
What to do now
- Remove ctx from every environment where it is installed.
- If ctx or the bad phpass ran, rotate every secret in the environment variables of that host, especially AWS keys.
- Review AWS CloudTrail for use of those keys after May 2022.
- For PHP, use a maintained phpass fork or a trusted hash library. Pin the commit hash in
composer.lock. - Block the Heroku host at the network edge.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 48 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED ctx/__init__.py It now reads saved passwords and access keys. It did not before.
Frequently asked questions
Which ctx versions on PyPI were malicious?
Sonatype lists ctx 0.2.2 and 0.2.6 as malicious, and says later versions also held the code. The attacker also replaced the old 0.1.2 release with tainted code.
How did the attacker take over the ctx package?
The attacker bought the expired domain of the maintainer's email address on 14 May 2022. The attacker then used the PyPI password reset to take over the account.
Sources
More supply chain attacks
- Microsoft durabletask PyPI compromise (TeamPCP) 19 May 2026
- LiteLLM PyPI backdoor (TeamPCP) 24 Mar 2026
- num2words hijack (PyPI phishing campaign / Scavenger malware) 28 Jul 2025
- Ultralytics PyPI compromise (GitHub Actions cache poisoning) 4 Dec 2024
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.