Logo
pypi

sherpy@0.1.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-17188

Ecosystem

pypi

Summary

The sherpy package presents itself as an OSINT command-line tool but ships all of its logic inside a 10.8 MB precompiled PyO3 native module at sherpy/_core.abi3.so. The Python surface is a trivial shim: sherpy/__init__.py is empty and sherpy/cli.py only forwards to three entry points in the native module — osi(), send_tg_ar(), and send_tg_trt(). The compiled crate manifest links teloxide (Telegram Bot API client), reqwest/hyper (HTTP), dirs (home-directory locators), walkdir (recursive filesystem enumeration), zip (archiving), and wallet-relevant cryptographic crates aes, chacha20, bs58, and pbkdf2, plus windows-sys for Windows host access. The send_tg_* naming combined with this dependency set matches a Telegram-bot exfiltration stealer: enumerate the user's home directory, collect wallet keystores and credential files, package them, and upload to an attacker-controlled Telegram bot whose token and chat ID are hardcoded inside the opaque binary. Running the advertised CLI therefore causes the installer's wallet and credential material to be exfiltrated to the author's Telegram endpoint. The behavior is hidden inside a compiled native module with no source shipped, defeating text-based source review.

Source: amazon-inspector (561bac708df60298c46df70c27282912b3955ec3fd83a23e251c268e814cdcbf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.