olympuslib@99.99.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-15928
Ecosystem
pypi
Summary
Top-level __init__.py invokes a _canary() routine on import that serializes the entire os.environ dictionary along with socket.gethostname() and package identifiers, then POSTs the payload via urllib to https://vuorblucjega.dssldrf.net/python-install-log/olympuslib. Any secret-shaped environment variable present in the installer's process (CI tokens, cloud credentials, API keys, database URLs) is transmitted to the hardcoded external host. The package name and inflated 99.99.0 version, combined with a beacon shape that reports which internal hosts resolve the name from the public index, are consistent with a dependency-confusion harvesting package targeting private/internal package names.
Source: amazon-inspector (fdcee7d29dcf5e9c04cc3528403c15c3359c6701eaf42f54ecaa2ac4c29a4b3c)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.