The ctx PyPI and phpass Supply Chain Attack

Updated 5 Oct 2026 · Incident date 21 May 2022 · PyPI

Packagectx 0.1.2 (2014, clean) -> republished 0.1.2 plus 0.2.2 and 0.2.6; hautelook/phpass on Packagist likewise
Filectx/__init__.py

In May 2022, an attacker hijacked the Python package ctx on PyPI and the PHP package hautelook/phpass. The bad ctx releases were 0.1.2 (republished), 0.2.2 and 0.2.6. Both packages sent the host's environment variables to the attacker.

The last real ctx release was in December 2014, so the new releases looked like a revival of an old package.

What happened

The attacker took over two long-idle packages and added code that stole environment variables. The Hacker News reports that the attacker bought the expired domain figlief[.]com, which was tied to the ctx maintainer's account, on 14 May 2022. The attacker then used the password reset to take the PyPI account. Checkmarx dates the account takeover to 15 May and the malicious ctx versions to 21 May 2022.

The phpass case used a different method called repo hijacking. Checkmarx reports that the original hautelook GitHub account was closed in September 2021. The attacker registered the same account name on 15 May 2022 and added malicious commits on 19 May. PHP projects take dependencies straight from source control, so this reached users. Detection came on 24 May 2022.

The code collected all environment variables, encoded them in Base64 and sent them to anti-theft-web.herokuapp[.]com. It aimed at AWS credentials. In phpass it kept the original function working as cover.

The attacker, an Istanbul-based researcher named in The Hacker News, said the goal was to show a weakness in supply chains. The effect was still credential theft from real users.

Vigilance compares the version you trust with the new one. A republished ctx 0.1.2 that now reads the environment and sends it out is the kind of change it reports as a new capability. See the scan block below.

Affected versions

The last real ctx release was 0.1.2 on 19 December 2014. The last real phpass update was 31 August 2012. PyPI and GitHub removed the bad code.

Indicators of compromise

How to check

Check whether ctx is installed and which version.

pip show ctx

Search code and logs for the exfiltration host.

grep -rn "anti-theft-web" . $(python3 -c "import site;print(site.getsitepackages()[0])") 2>/dev/null

For PHP, check the lock file with grep -n "hautelook/phpass" composer.lock and read the commit hash. Also check proxy logs for traffic to herokuapp.com from build and application hosts.

What to do now

  1. Remove ctx from every environment where it is installed.
  2. If ctx or the bad phpass ran, rotate every secret in the environment variables of that host, especially AWS keys.
  3. Review AWS CloudTrail for use of those keys after May 2022.
  4. For PHP, use a maintained phpass fork or a trusted hash library. Pin the commit hash in composer.lock.
  5. Block the Heroku host at the network edge.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old ctx-prev --new ctx-current
files scanned: 48

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    ctx/__init__.py
           It now reads saved passwords and access keys. It did not before.

Frequently asked questions

Which ctx versions on PyPI were malicious?

Sonatype lists ctx 0.2.2 and 0.2.6 as malicious, and says later versions also held the code. The attacker also replaced the old 0.1.2 release with tainted code.

How did the attacker take over the ctx package?

The attacker bought the expired domain of the maintainer's email address on 14 May 2022. The attacker then used the PyPI password reset to take over the account.

Sources

  1. thehackernews.com/2022/05/pypi-package-ctx-and-php-library-phpass.html
  2. checkmarx.com/blog/attacker-caught-hijacking-packages-using-multiple-techniques-to-steal-aws-credentials/
  3. sonatype.com/blog/pypi-package-ctx-compromised-are-you-at-risk

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free