thumbnail PyPI package 'ctx' and PHP library 'phpass' compromised to steal environment variables