metrio@1001.0.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC
OSV ID
MAL-2026-17193
Ecosystem
pypi
Summary
metrio 999.0.0 executes a hostname-exfiltration beacon from both setup.py (install time) and metrio/__init__.py (import time). The code reads the local machine's hostname, hex-encodes it, and embeds it as a subdomain of the attacker-controlled domain 84avt3516s4q1obsv9q0mh4u2l8dw3ks.x9.to, then triggers a DNS resolution via socket.gethostbyname and a plain-HTTP GET via urllib.request.urlopen against that host. The version number 999.0.0 and the self-described 'dependency-confusion PoC placeholder' summary are the canonical high-version dependency-confusion shape: the package is intended to win resolution against an internal package of the same name and beacon the resolving host back to the operator. Installer harm on pip install metrio or import metrio is disclosure of the installer's hostname to a third-party collector, and confirmation to the operator that this internal name resolves to the public index from the installer's build environment.
Source: amazon-inspector (ce8ee66a844d7abed74f4b9d223c8ef8f35bae380104526f4f8bc57295c47320)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.