cubesat-upstream-driver@1.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC
OSV ID
MAL-2026-13666
Ecosystem
pypi
Summary
The package is advertised as an 'Upstream driver interface for cubesat orbital command bus' but ships no driver, protocol, or telemetry code. Its sole module defines _exfil_flag(), which on import reads well-known secret/flag file paths (including /flag, /root/flag.txt, and /**/flag* globs), scans os.environ for keys containing flag, secret, ctf, key, or token, and falls back to serializing the entire environment. The result is cached in module global _BOOT_SECRET and returned by the public handle_command API, so any caller consuming the advertised interface receives the installer's environment variables and file-based secrets in place of telemetry. handle_command also re-runs the harvest on each invocation.
Source: amazon-inspector (1f5f2cf32e29ec0daedda5112ca2c560e69b4c4cd77850d6dc52d7a448e343a2)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.