Logo
pypi

kb-ai@0.1.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 6:41 AM UTC

Malicious

OSV ID

MAL-2026-14069

Ecosystem

pypi

Summary

On import kb_ai, the package's __init__.py triggers kb_ai.utils.callback, which starts a background thread that collects installer host identifiers (hostname, platform, Python version, timestamp) and POSTs them to a hardcoded Azure-hosted endpoint at bybitpoc-f2b2b4gfbefufvfc.canadacentral-01.azurewebsites.net/callback. The network call is unconditional, fires without caller opt-in, and errors are silently swallowed. The module's own comments describe the behavior as a supply-chain proof-of-concept.

Source: amazon-inspector (3d69143a6cdc0a652f91210034751420f7ada3db2a13d81d9e635e3a63333dc5)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.