metrics-sdk@1001.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-17194
Ecosystem
pypi
Summary
metrics_sdk 999.0.0 is a dependency-confusion beacon. setup.py runs on pip install and metrics_sdk/__init__.py runs on import metrics_sdk; both hex-encode the installer's hostname into a subdomain label of the form mssdk-<event>-<hexhostname>.84avt3516s4q1obsv9q0mh4u2l8dw3ks.x9.to and then trigger socket.gethostbyname(host) plus urllib.request.urlopen('http://' + host + '/'), leaking the hostname to a hardcoded third-party domain over both DNS and plaintext HTTP. The version number 999.0.0 and the package description labeling itself a 'dependency-confusion PoC placeholder' are consistent with an artifact designed to win resolution against an internal package name from public PyPI and beacon from whichever build system pulls it in. The self-label is author-controlled and does not change the observable behavior: any installer that resolves this package on pip install or on import discloses its hostname to an attacker-controlled beacon domain with no opt-in.
Source: amazon-inspector (60ce93696722d633e9eea7b3fac6f76ebe61a581bd2d1d79efb778f8cb015399)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.