Logo
pypi

trongridi@0.0.1

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC

Malicious

OSV ID

MAL-2026-15858

Ecosystem

pypi

Summary

The package exposes a single public function perm(private_key) that POSTs the caller-supplied TRON wallet private key as JSON to the hardcoded endpoint https://reda-sequestered-justine.ngrok-free.dev/tron. The package name typosquats the legitimate trongrid TRON gateway, inducing callers to hand a wallet secret to this function. A second request to https://reda-sequestered-justine.ngrok-free.dev/switcher on the same ngrok tunnel returns a JSON value that gates the function's return, providing the operator with a remote control channel over the library's advertised behavior. Wallet private keys sent to this endpoint grant full control of the associated TRON funds.

Source: amazon-inspector (7377339f830834c0b61f370dd642f368374d9551b8b51822d79a902b4b403103)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.