Logo
pypi

neutrl-contracts@2.0.2

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:38 AM UTC

Malicious

OSV ID

MAL-2026-13709

Ecosystem

pypi

Summary

Review of neutrl-contracts 2.0.2 on PyPI did not surface any code paths that exfiltrate installer data, execute attacker-controlled payloads at install or import time, relay caller data to a hardcoded third-party destination, ship live third-party credentials, or establish a backdoor. No install-time network I/O, no lifecycle-hook shell execution, and no credential or filesystem reconnaissance were observed in the package's files.

Source: amazon-inspector (b41aff3f07d1c63f5b9c6096798ce5ce7cb3b06028f1bc6361e9501c966742a0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.