dbt-sa-cli@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-15934
Ecosystem
pypi
Summary
setup.py defines rce_poc() and invokes it at module top level, so the code runs unconditionally during pip install dbt-sa-cli. The function collects installer-side identifiers (hostname, USER/USERNAME, current working directory, home path) and sends them out-of-band via a DNS lookup to a subdomain of yokodnssmamqdchvjfyqyo8zaq3s90h8e.oast.fun and an HTTPS POST to https://yokodnssmamqdchvjfyqyo8zaq3s90h8e.oast.fun/dbt-sa-cli. The same install-time path drops a marker file at ~/.dbt-sa-cli-rce-poc in the installer's home directory, demonstrating arbitrary code execution during install. The package name resembles the dbt ecosystem, making this a typosquat lure. Regardless of any 'security research' framing, installing the package produces immediate installer-side data disclosure and code execution against an author-controlled OOB collector.
Source: amazon-inspector (9a3fc52d1baa65bd51dd9659641f0df237ea2a595358cd91b19fd8988ba3236a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.