OSV ID
MAL-2026-13729
Ecosystem
pypi
Summary
The package's top-level module runs a report() routine on import, and setup.py invokes the same import at install time. The routine collects environment variables matching secret-shaped keywords (KEY, TOKEN, SECRET, AWS, GITHUB, NPM, MNEMONIC, WALLET, SOLANA, HELIUS,...), reads ~/.npmrc and ~/.gitconfig, enumerates ~/.ssh, ~/.aws, ~/.config/solana, ~/.config/anchor, and ~/.config/gcloud, and gathers hostname, username, cwd, and platform. The collected JSON is POSTed via urllib.request.urlopen to a hardcoded webhook.site endpoint (https://webhook.site/326b0891-2093-4800-a4c1-686ce3e07b09). Module docstring and setup.py comment label the behavior 'environment diagnostics,' but the code path is bulk credential and host-identity exfiltration to a non-first-party collector. The package name resembles Meteora's DLMM SDK.
Source: amazon-inspector (9ddf2d03d839f7eff709e78da1d6a85226cdd3b9171dbcb59a4a95c741e0773e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.