🚀 Socket Launch Week Day 5:Introducing Repository Access Permissions and Custom Roles.Learn more
Sign In

dd-trace-api-py

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

dd-trace-api-py

Security research PoC - pip takeover for DataDog dd-trace-api-py

pipPyPI
Version
0.0.1
Weekly downloads
115
Maintainers
1
Weekly downloads
 

dd-trace-api-py

Security Research - Package Takeover PoC

This package was registered as part of responsible security research.

The package name dd-trace-api-py is referenced in official Datadog documentation (dd-trace-api-py quickstart) but was not registered on PyPI, making it vulnerable to supply chain takeover via pip install dd-trace-api-py.

The real Datadog tracer package on PyPI is ddtrace — docs use a different name.

Impact

Any developer following official docs who runs the documented command would execute attacker-controlled code.

This package is harmless

It only prints a warning message. No data is collected.

Researcher

AnupamAS01

Keywords

security-research

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts