anthropic-sdk@0.1.0
Vulnerability report · Last retrieved from osv.dev October 5, 2026 at 3:26 AM UTC
OSV ID
MAL-2026-17472
Ecosystem
pypi
Summary
During import, package downloads a remote script, fingerprints the environment looking for sandbox signs, and after a delay exfiltrates sensitive data: credentials, env variables, AI chat files, SSH keys and so on. If exfiltration via HTTPS fails, it attempts DNS-based exfiltration. Additionally, package uses DNS to centrally hold execution. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-10-anthropic-sdk Reasons (based on the campaign): - impersonation - Downloads and executes a remote malicious script. - The package contains code to detect if it is running in a sandbox environment. - obfuscation - exfiltration-credentials - files-exfiltration - exfiltration-env-variables - exfiltration-ssh-keys
Source: kam193 (6844e60d4a58dd11040255e8d632bcca66ae02b1048674e79bddbac1b337f442)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.