Logo
pypi

mlflow-ui@2.7.3

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-10779

Ecosystem

pypi

Summary

The package impersonates the MLflow project (author 'MLflow Community' <community@mlflow.org>, homepage https://github.com/mlflow/mlflow) but provides no MLflow UI functionality. Both setup.py (install time) and mlflow_ui/__init__.py (import time) execute payload_core.py, which collects hostname, platform, the full process environment (dict(os.environ)), /etc/hosts, /etc/resolv.conf, /proc/self/cgroup, /proc/1/cmdline, directory listings of /, /app, /opt, /srv, /home, /tmp, and the output of id, ps aux, and ip addr, along with internal-network probe results. The data is base64-encoded and POSTed to https://webhook.site/9510ba0a-29f7-4ce6-afe7-632c92cf0f41/piprecon over TLS with verification disabled (ssl._create_unverified_context()). The same module fetches a second-stage Python payload from https://webhook.site/a9f5802b-c77e-4226-99dd-bc89d7dc8cca/s2.py and passes the bytes to compile()+exec() with subprocess and os bound in globals, yielding arbitrary remote code execution on the installer's host at both install and import time. Bulk environment scraping captures AWS_*, GH_TOKEN, npm/PyPI tokens, database URLs, and any other CI/build secrets present.

Source: amazon-inspector (b7192c53fc1e0b62e2c373a8a6beabfeb3777cae3aacfe23ca374eab1c2839a7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.