Re: Questionable package in PyPi, maybe malicious

Bert JW Regeer <[email protected]> Sat, 21 Mar 2020 01:18:04 -0700
Newsgroups gmane.comp.python.distutils.devel
Message-ID <[email protected]>
The package contains two files, and basically prints out:

"You probably meant to install flask-migrate"

It is meant to make sure that no-one else squats on the name and uses it to exploit unsuspecting users that install the wrong package.

Bert JW Regeer

> On Mar 21, 2020, at 01:09, Evagelos <[email protected]> wrote:
> 
> Hi there,
> 
> I searched PyPi for "flaskmigrate" and this came up:
> flaskmigrate - A package to prevent exploit
> 
> Seems strange to me so I wanted to make you aware, I was advised to report in this mailing list.
> 
> Regards,
> Evagelos
> --
> Distutils-SIG mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> https://mail.python.org/mailman3/lists/distutils-sig.python.org/
> Message archived at https://mail.python.org/archives/list/[email protected]/message/D5EISUDCPU6DMWG2CJK6RK6TZSJXSWD5/
--
Distutils-SIG mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3/lists/distutils-sig.python.org/
Message archived at https://mail.python.org/archives/list/[email protected]/message/O4OM744BSRP5YY3F3XISHDIU5LCQBVH5/