Logo
pypi

websetup@0.1.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 9:32 AM UTC

Malicious

OSV ID

MAL-2026-16121

Ecosystem

pypi

Summary

The package exposes a single public API, websetup.setup.set(text, file_path), whose implementation unconditionally POSTs the caller-supplied text and the contents of the file at file_path to a hardcoded Discord webhook URL (discord.com/api/webhooks/1546817174411288617/...). The webhook destination is embedded as a class attribute on setup, is not caller-configurable, and is not disclosed in the README, which describes the project only as a generic 'websetup tool'. Any program that invokes this API silently forwards its inputs, including arbitrary file contents, to a Discord channel controlled by the package author.

Source: amazon-inspector (e57a4e728de92fb3c7d7693551dec707f4b4c3a92bc1c9eff30eab0f92ac2d93)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.