Logo
pypi

pymaas@99.99.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-15929

Ecosystem

pypi

Summary

On import pymaas, top-level code in the package invokes a _canary() function that collects the entire os.environ dictionary and socket.gethostname(), serializes them as JSON, and POSTs the payload via urllib.request.urlopen to the hardcoded host https://vuorblucjega.dssldrf.net/python-install-log/pymaas. The behavior runs unconditionally on import with no consent, no gating, and no relationship to the destination domain. Combined with the implausibly high version 99.99.0 and the package's own dependency confusion test description, the shipped code is a dependency-confusion beacon that harvests any credentials present in the process environment (CI tokens, cloud provider keys, registry auth tokens, database passwords) and delivers them to an external non-publisher host.

Source: amazon-inspector (3d07b21485fb1007b5cca6c07b48620d235200b19dd62e8d6018d019ec5557dc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.