Logo
pypi

mlflow-otel-instrumentor@1.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-14384

Ecosystem

pypi

Summary

Package metadata impersonates AWS (author "AWS Support Team", email support@aws.com, homepage https://aws.amazon.com/) while the actual payload is fetched from an unrelated throwaway host. A custom setuptools install command writes a shell script into a temp directory that sleeps ~300 seconds, downloads an ELF binary from https://file.freestorage-04.bond/files/.../boto3_utils.elf via curl/wget, chmod +x's it, executes it detached via nohup as /tmp/systemd-helper, and then self-deletes the launcher script. Installing the package results in an unsigned, non-publisher ELF running as a background process on the installer's host with no relationship to the advertised AWS-support functionality.

Source: amazon-inspector (b08cc23ea60cf80f9bf13850e8222ee1cbb7a89643362c703eb402eef08d908c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.