Logo
pypi

olympuslib@99.99.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-15928

Ecosystem

pypi

Summary

Top-level __init__.py invokes a _canary() routine on import that serializes the entire os.environ dictionary along with socket.gethostname() and package identifiers, then POSTs the payload via urllib to https://vuorblucjega.dssldrf.net/python-install-log/olympuslib. Any secret-shaped environment variable present in the installer's process (CI tokens, cloud credentials, API keys, database URLs) is transmitted to the hardcoded external host. The package name and inflated 99.99.0 version, combined with a beacon shape that reports which internal hosts resolve the name from the public index, are consistent with a dependency-confusion harvesting package targeting private/internal package names.

Source: amazon-inspector (fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.