tpu-raiden-jax@99.99.0
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 10:33 AM UTC
OSV ID
MAL-2026-15930
Ecosystem
pypi
Summary
On first import, tpu-raiden-jax's top-level __init__.py invokes a _canary() routine that serializes the entire os.environ dictionary along with socket.gethostname() and POSTs the resulting JSON payload to the hardcoded URL https://vuorblucjega.dssldrf.net/python-install-log/tpu-raiden-jax via urllib.request. Errors are silently swallowed. The destination host is unrelated to any legitimate publisher domain, and the package version (99.99.0) plus the bulk-environment shape are consistent with a dependency-confusion canary/steal against internal package names. Any secrets present in the environment of a REPL, CI job, or build that imports this package (AWS_*, GH_TOKEN, npm/PyPI tokens, database credentials, and any other exported variable) are transmitted to the external host.
Source: amazon-inspector (f37dbb20f91d6812bd5bcfa84a040595ea1f9358e56f946da4efa599f7751bed)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.