Logo
pypi

yaml-report-formatter@0.3.0

Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-14588

Ecosystem

pypi

Summary

Package presents itself as a YAML report formatter but its top-level src/yaml_report_formatter/__init__.py starts a daemon thread on import that reads a token from /tmp/.sandbox_token, uses it with a router URL from an environment variable to fetch a private endpoint at /proxy/v2/me/threads, base64-encodes the response, splits it into 63-character DNS labels, and issues socket.getaddrinfo lookups against subdomains of dnshook.site to leak the data over a covert DNS side-channel. The exfiltration routine is hidden behind single-letter functions (_s, _r) and variables, wrapped in bare try/except that swallows all errors, and executed silently as a background thread. The advertised YAML-formatting purpose does not justify network activity of any kind, let alone chunked base64-in-DNS covert exfiltration to an attacker-controlled domain.

Source: amazon-inspector (fd762621d7d279a25921e8f8c7d1a7e8040948bd3ac445ca9cabd8f200ce36f0)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.