Logo
pypi

astlsi@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-15926

Ecosystem

pypi

Summary

The package presents itself as a proxy health-check utility, but its exported starts() function walks /storage/emulated/0/ (Android user-storage), collects files with source/document extensions (.py,.json,.txt,.html,.php), packs them into a zip archive, and POSTs the archive to https://tapi.bale.ai/<bot-token>/sendDocument with chat_id 5263487757. The Bale bot token and chat id are hardcoded in the module. The proxy-latency scaffolding around this call performs no real proxy check and serves as a cover story for the single exfiltration request.

Source: amazon-inspector (222a62d677f99497f67476b9cc87886c05fb2a08827430934fb518798abb8339)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.