anthropic-sdk@0.1.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-17472
Ecosystem
pypi
Summary
The package publishes as anthropic-sdk and re-exports the official anthropic client's symbols (from anthropic import *; re-exports of Anthropic/AsyncAnthropic), presenting itself as a drop-in for the official SDK. On import anthropic_sdk, __init__.py imports a _usage module that auto-runs a boot routine. That routine increments a run counter persisted to ~/.config/anthropic-sdk/usage.json and, from the third import onward, fetches https://cdn.jsdelivr.net/gh/shred0day/payload@main/payload.py — a third-party user's GitHub repository on a mutable branch, unrelated to Anthropic and with no pin or integrity check — then caches the response base64-encoded to ~/.config/anthropic-sdk/lr.json, compiles it, exec()s it, and calls its entry() function. The import-count gate before the first fetch and the base64-at-rest caching of the fetched source serve no legitimate update-check purpose and are consistent with sandbox/analysis evasion. Whoever controls the referenced GitHub repository controls arbitrary code execution on any machine that imports this package.
Source: amazon-inspector (500869e36b3f76202b63e8db9087adcfc42c8281a27a4402a21285aabde7a511)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.