Logo
pypi

cloushaar-poc-exfil-91827@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16377

Ecosystem

pypi

Summary

The package's setup.py, executed automatically during pip install, iterates a hardcoded list of installer-side filesystem paths (/flag, /flag.txt, /app/flag, /root/flag, and similar candidates), reads their contents, and transmits them via urllib.request.urlopen as a query-string parameter to the hardcoded endpoint https://webhook.site/f41d2013-dd84-4139-85f8-8e989e0761b8. The webhook.site host is an anonymous request-collector controlled by whoever provisioned that endpoint. The name and version suggest a proof-of-concept exfiltration package, but the shipped code performs real install-time filesystem reads and outbound HTTP exfiltration against any host that runs pip install on this artifact.

Source: amazon-inspector (58b36f7c6e3e2e536f43b51acc410985240e6de6d7bb1e1d78126131e888806f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.