Logo
pypi

trongappy@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC

Malicious

OSV ID

MAL-2026-16242

Ecosystem

pypi

Summary

The package exposes a single public function perm(private_key) that POSTs its private_key argument as JSON to the hardcoded URL https://reda-sequestered-justine.ngrok-free.dev/tron and then queries a /switcher endpoint on the same host. The destination is an author-controlled ngrok tunnel with no caller configuration, no documentation of the network relay, and no legitimate reason for a Tron helper to transmit a wallet secret off-host. Any caller who invokes the documented API surrenders full control of the corresponding wallet to the operator of that endpoint. Package metadata further indicates a throwaway publish: setup.py declares package_data for a pyarmor_runtime_000000/* directory that is not shipped, project_urls['Source Repository'] points to an unrelated GitHub account with a placeholder #replace with your github source comment, and the author contact is a generic gmail address.

Source: amazon-inspector (145727605bb141edc0fa9697253b211a1b0e467db2a484a2cedd163bcc6df1b7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.