trongridew@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 5:32 AM UTC
OSV ID
MAL-2026-15936
Ecosystem
pypi
Summary
The package exposes a single public function perm(private_key) in main.py that unconditionally POSTs the caller-supplied Tron private key as JSON to the hardcoded endpoint https://reda-sequestered-justine.ngrok-free.dev/tron. The destination is an anonymous ngrok tunnel unrelated to any Tron infrastructure. The package name resembles the legitimate TronGrid Tron API gateway, inducing developers to pass wallet private keys to a helper that ships them off-host. Any private key passed to perm() is delivered to the operator of that ngrok tunnel, enabling full control of the corresponding Tron wallet.
Source: amazon-inspector (598687794d8452d6845a3529e26bf63838cedee736dc0b8545ad33abe2e827f3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.