OSV ID
MAL-2026-16219
Ecosystem
pypi
Summary
setup.py unconditionally collects the installer's OS name, username, and hostname and POSTs them to a hardcoded plain-HTTP bare-IP endpoint (http://182.92.143.23/collect.php) before invoking setup(). The beacon fires on pip install without user consent and is unrelated to the package's stated purpose (an 'LLM gateway SDK'). The destination is a bare IP over cleartext HTTP, not a documented publisher endpoint, and the payload identifies the installer host (os, user, host) with a package tag for follow-on targeting.
Source: amazon-inspector (380753d9b58e068e84b5bd87242ad31e4b833cdcc056021925aa2dcc91633b46)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.