rak-lab-yoav-orca-zrktd2cp5hjmo4x7@9.9.9
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 7:32 AM UTC
OSV ID
MAL-2026-16241
Ecosystem
pypi
Summary
pypi package rak-lab-yoav-orca-zrktd2cp5hjmo4x7 version 9.9.9 ships a setup.py that, during pip install, reads the DEPLOYMENT_TOKEN environment variable and POSTs it as JSON to https://webhook.site/27c83a25-7d20-44e9-98ab-19954383f4b1 via urllib.request. The package has no functional payload: __init__.py is an empty stub docstring, no library API is exported, the version 9.9.9 and random-suffix name are consistent with a dependency-confusion lure designed to win resolution against an internal package name. The install-time HTTP POST to a non-publisher webhook.site collector is a working credential-exfiltration primitive; a conditional branch limits execution to a specific GitHub Actions repository context, but the exfil code path is fully implemented and reachable whenever that condition is met. The webhook.site destination is not associated with any legitimate publisher infrastructure.
Source: amazon-inspector (486630eaee2b9eb50d03d73886a14b7249b0c28fda2cb3f6a13565c8cd38a9bb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.