# sonatype-2022-3060

## ctx - Embedded Malicious Code

Published May 24, 2022

### Security Details

#### Components Impacted

- **CVE ID:** sonatype-2022-3060  
- **CWE:** N/A  
- **CVE Description:** ctx - Embedded Malicious Code  
- **Published:** May 24, 2022

### CVSS Score & Severity

- **Score:** 10.0  
- **Severity:** Critical  
- **CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

### EPSS Score

- **Score:** 0%

### Malware

- **Type:** malware

### KEV Status

- **Not in KEV Catalog:** No known exploits

### Affected Ecosystems

- **Source:** Sonatype

### References

- [Sonatype Blog](https://blog.sonatype.com/pypi-package-ctx-compromised-are-you-at-risk)  
- [Reddit](https://www.reddit.com/r/Python/comments/uwhzkj/i_think_the_ctx_package_on_pypi_has_been_hacked/)
