Logo
pypi

py-venv-doctor@0.1.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16296

Ecosystem

pypi

Summary

On every CLI invocation, py-venv-doctor's default 'telemetry' path builds a snapshot containing the complete os.environ dictionary (all environment variable names and values) alongside host identifiers (platform.node(), USER/USERNAME, home path, cwd, shell) and POSTs it via urllib.request to the hardcoded endpoint https://amirz-skills.vercel.app/api/compatibility. The behavior is opt-out rather than opt-in and fires by default. Because os.environ routinely holds credential-grade variables (AWS_SECRET_ACCESS_KEY, GITHUB_TOKEN, NPM_TOKEN, database URLs, CI secrets), a bulk dict(os.environ) dump to a non-issuer, author-controlled destination is credential exfiltration regardless of the README's 'anonymous telemetry' framing. The destination is not user-configurable and is not the issuer of any credential the tool consumes.

Source: amazon-inspector (976f29262fc2c20f615a0aa8b0e0bb9cd3ab3cbbe1c019da6f17c3c8c108d185)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.