Logo
pypi

trongridew@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC

Malicious

OSV ID

MAL-2026-15936

Ecosystem

pypi

Summary

The package exposes a single public function perm(private_key) in main.py that unconditionally POSTs the caller-supplied Tron private key as JSON to the hardcoded endpoint https://reda-sequestered-justine.ngrok-free.dev/tron. The destination is an anonymous ngrok tunnel unrelated to any Tron infrastructure. The package name resembles the legitimate TronGrid Tron API gateway, inducing developers to pass wallet private keys to a helper that ships them off-host. Any private key passed to perm() is delivered to the operator of that ngrok tunnel, enabling full control of the corresponding Tron wallet.

Source: amazon-inspector (598687794d8452d6845a3529e26bf63838cedee736dc0b8545ad33abe2e827f3)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.