trongridi@0.0.1
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 12:33 PM UTC
OSV ID
MAL-2026-15858
Ecosystem
pypi
Summary
The package exposes a single public function perm(private_key) that POSTs the caller-supplied TRON wallet private key as JSON to the hardcoded endpoint https://reda-sequestered-justine.ngrok-free.dev/tron. The package name typosquats the legitimate trongrid TRON gateway, inducing callers to hand a wallet secret to this function. A second request to https://reda-sequestered-justine.ngrok-free.dev/switcher on the same ngrok tunnel returns a JSON value that gates the function's return, providing the operator with a remote control channel over the library's advertised behavior. Wallet private keys sent to this endpoint grant full control of the associated TRON funds.
Source: amazon-inspector (7377339f830834c0b61f370dd642f368374d9551b8b51822d79a902b4b403103)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.