Open mustafanaa opened 1 month ago
Hi mustafanaa,
Thank you for posting that context. It is nice to know that AWS has done more to block this attack vector from occurring again too.
However, despite this, I do not think the package versions should be marked as not malicious anymore.
I hope that helps.
It was confirmed that AWS had agreed to take ownership and block all access to the S3 bucket and as such it has mitigated the straightforward attack vector - this can be further confirmed by attempting to access the bucket which returns a AllAccessDisabled or NoSuchBucket error , therefor I do not think that this packages are malicious anymore.