A popular Python library just became a backdoor to your entire machine
… Here's the full list, according to the opened GitHub issue: System info: hostname, whoami, uname -a, ip addr, ip route Environment variables: printenv captures all API keys, secrets, tokens SSH keys: ~/.ssh/id rsa, ~/.ssh/id ed25519, ~/.ssh/id ecdsa, ~/.ssh/id dsa, ~/.ssh/authorized keys, ~/.ssh/kn… …