Logo
pypi

licloud@0.2.8

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 11:33 AM UTC

Malicious

OSV ID

MAL-2026-16219

Ecosystem

pypi

Summary

setup.py unconditionally collects the installer's OS name, username, and hostname and POSTs them to a hardcoded plain-HTTP bare-IP endpoint (http://182.92.143.23/collect.php) before invoking setup(). The beacon fires on pip install without user consent and is unrelated to the package's stated purpose (an 'LLM gateway SDK'). The destination is a bare IP over cleartext HTTP, not a documented publisher endpoint, and the payload identifies the installer host (os, user, host) with a package tag for follow-on targeting.

Source: amazon-inspector (380753d9b58e068e84b5bd87242ad31e4b833cdcc056021925aa2dcc91633b46)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.