metricboxlite@2.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-15931
Ecosystem
pypi
Summary
MetricBoxLite 1.0 collects the installer's username (getpass.getuser) and hostname (socket.gethostname), JSON-encodes them, and POSTs the payload to a hardcoded remote endpoint at https://kznkrxfzy4xgib6ejfh8etegndp3kwguf.oast.invalid/collect. The beacon fires from two independent paths: setup.py calls the reporter at module top level, so it runs during pip install of the sdist, and metricboxlite/__init__.py performs the same collect-and-POST at top level, so any import metricboxlite also phones home. Network errors are silently swallowed. The destination is an OAST/out-of-band-callback host that is not first-party to the package or its ecosystem, and the collected fields are installer identity rather than package operational data.
Source: amazon-inspector (d5a511a75c8c42dcd677dd3814265d3befefa7f339bdc6b0336788635813e837)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.