Logo
pypi

metrio@1001.0.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC

Malicious

OSV ID

MAL-2026-17193

Ecosystem

pypi

Summary

metrio 999.0.0 executes a hostname-exfiltration beacon from both setup.py (install time) and metrio/__init__.py (import time). The code reads the local machine's hostname, hex-encodes it, and embeds it as a subdomain of the attacker-controlled domain 84avt3516s4q1obsv9q0mh4u2l8dw3ks.x9.to, then triggers a DNS resolution via socket.gethostbyname and a plain-HTTP GET via urllib.request.urlopen against that host. The version number 999.0.0 and the self-described 'dependency-confusion PoC placeholder' summary are the canonical high-version dependency-confusion shape: the package is intended to win resolution against an internal package of the same name and beacon the resolving host back to the operator. Installer harm on pip install metrio or import metrio is disclosure of the installer's hostname to a third-party collector, and confirmation to the operator that this internal name resolves to the public index from the installer's build environment.

Source: amazon-inspector (ce8ee66a844d7abed74f4b9d223c8ef8f35bae380104526f4f8bc57295c47320)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.