Logo
pypi

azure-langchain-example@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 1:33 PM UTC

Malicious

OSV ID

MAL-2026-17213

Ecosystem

pypi

Summary

On import azure_langchain_example, the package's __init__.py starts a background daemon thread that issues a GET request to https://litellm.adversarylabx.com/.telemetry with the installer's hostname, resolved IP address, a timestamp, and the package name in the query string, using urllib.request.urlopen with a short timeout and silenced exceptions. The destination host is unrelated to the package's advertised purpose (a minimal LangChain wrapper for Azure OpenAI) and to any Azure or LangChain publisher domain. The behavior fires unconditionally at import without user consent or opt-out and is not mentioned in the README. Package metadata is placeholder (Your Name <you@example.com>) and the name resembles the Azure+LangChain ecosystem, consistent with a lookalike used to profile installers who mistype or guess an Azure/LangChain integration package name. An in-source comment labeling the request a harmless canary is author-controlled text that does not change the observed behavior.

Source: amazon-inspector (1cffc3a51858b1b7a17ff0edfd2eeae6383e83b4eff5bc078f7b1d4f5ba36ad2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.