The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
"https://github.com/pypa/advisory-database/blob/main/vulns/keep/PYSEC-2022-43056.yaml"