Skip to main content

EDUCATIONAL DEMO: Executes code at install time to play the rickroll video. The purpose is to demonstrate supply chain security risks to students in a memorable way so that they will be careful with what they install in the future.

Project description

superfancyjoketools

This is a project to teach students about dependency injection and other pypi security risks. When installed, it runs the rickroll video in order to demonstrate to students that arbitrary code can be run when installing a python project via pip, and the hope is that this is a memorable event for students so they are careful when installing packages in the future.

Installation instructions are included in a separate lab and so this project shouldn't be ever accidentally installed by non-students.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

supply_chain_attack_poc-0.1.1.tar.gz (4.9 kB view details)

Uploaded Source

File details

Details for the file supply_chain_attack_poc-0.1.1.tar.gz.

File metadata

  • Download URL: supply_chain_attack_poc-0.1.1.tar.gz
  • Upload date:
  • Size: 4.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.5

File hashes

Hashes for supply_chain_attack_poc-0.1.1.tar.gz
Algorithm Hash digest
SHA256 97b608508b25ef49c53d5426845cfb2e6b481d76571fc64700dd4f5864079873
MD5 e6b4ddadafe23605d0c24c04d46ce380
BLAKE2b-256 6c5213a71d7a9127ba9d2eaabef3a2f8d38867a027d00d550a22e0feac890da0

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page