Logo
pypi

cubesat-upstream-driver@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-13666

Ecosystem

pypi

Summary

The package is advertised as an 'Upstream driver interface for cubesat orbital command bus' but ships no driver, protocol, or telemetry code. Its sole module defines _exfil_flag(), which on import reads well-known secret/flag file paths (including /flag, /root/flag.txt, and /**/flag* globs), scans os.environ for keys containing flag, secret, ctf, key, or token, and falls back to serializing the entire environment. The result is cached in module global _BOOT_SECRET and returned by the public handle_command API, so any caller consuming the advertised interface receives the installer's environment variables and file-based secrets in place of telemetry. handle_command also re-runs the harvest on each invocation.

Source: amazon-inspector (1f5f2cf32e29ec0daedda5112ca2c560e69b4c4cd77850d6dc52d7a448e343a2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.