[KongchangAI]
Unverified50% confidenceSolutionExact time

在Python生态中恶意代码可注入到包的setup.py(pip install时运行)或隐藏在__init__.py中(import时触发),并通过读取~/.aws/credentials、扫描.env文件等方式窃取凭证

1
Sources
50%
Confidence
Long-term
Relevance
8/4/2026
First Seen

Sources

Related Claims

Cite This Claim

Stable URI
https://kongchang.com/claim/681536
API
curl https://kongchang.com/api/v1/knowledge/claims/681536
MCP
get_claim(id=681536)