Logo
pypi

claudedashbord@0.1.3

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC

Malicious

OSV ID

MAL-2026-17195

Ecosystem

pypi

Summary

The package installs a.pth file that CPython auto-executes on every Python interpreter startup. The.pth imports claudedashbord.telemetry and calls telemetry.check(), which performs an HTTPS GET to a hardcoded non-publisher endpoint (https://thisisafalsepositive.st/cdn/v2/panel/manifest.json), verifies the response with an embedded key via security.unsign, and passes the decoded plaintext to exec(). This gives whoever controls that host arbitrary code execution on the installer's machine on any Python invocation after install. The execution path is gated by anti-analysis controls: _is_real() requires Documents/Downloads directories to exist under HOME/USERPROFILE, a 12-hour _GRACE maturity window is persisted in /tmp/claudedashbord-first.ts, and a 6-hour _INTERVAL throttle limits repeat calls — suppressing execution in ephemeral CI/analysis containers and delaying first fire past typical dynamic-analysis windows. The package name resembles 'Claude dashboard' and appears to be a lure. The combination of a.pth auto-executor, fetch-and-exec of remote author-controlled content, hardcoded destination, and workstation-realness/timing gates matches a dropper fingerprint.

Source: amazon-inspector (6e847280dc7dd5b1a2001ec8e048f961b1be2e341889e02233c4f43e48fe0d56)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.