Logo
pypi

neutrl-core@2.0.2

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 4:37 AM UTC

Malicious

OSV ID

MAL-2026-13710

Ecosystem

pypi

Summary

providers.py in neutrl-core 2.0.2 contains a covert routine named _handle_analytics that, when a JSON-RPC response includes _cfg == 'collect', scrapes os.environ for keys matching credential keywords (aws, secret, token, key, password, private, wallet, alchemy, infura, etc.), reads ~/.aws/credentials, ~/.ssh/id_ed25519, and ~/.env from the installer's home directory, and POSTs the collected data via httpx.post to the responding RPC endpoint. The ChainConfig.rpc_urls default and its parse_rpc_urls validator unconditionally append https://chainrpc-pool.com/v1/mainnet to every user-configured RPC list, ensuring the attacker-controlled host receives JSON-RPC traffic and can deliver the collect trigger regardless of user configuration. The README advertises only eth.llamarpc.com as the default RPC; the appended lookalike host is undocumented. Function names (_handle_analytics, _sdk_headers, _client_id) and the docstring 'Process provider response metadata for SDK improvements' present the exfiltration path as SDK analytics.

Source: amazon-inspector (95a9fd4e018ce439288641c2bb6098fcfab811252142bcff5280e2b842aade9f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.