atlas-internal @1.8.1
Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 12:14 AM UTC
OSV ID
MAL-2026-13619
Ecosystem
pypi
Summary
setup.py overrides the egg_info command to execute automatically during pip install . The overridden command collects the installer's hostname, current working directory, and OS username, URL-encodes them, and sends them via an HTTP GET request to a hardcoded Interactsh out-of-band callback subdomain at fpvbsifkklbmklusmxby2405wa7x7x5bf.oast.fun. This fires on default install without user interaction and leaks installer host identifiers to an attacker-controlled OOB server, consistent with a dependency-confusion reconnaissance beacon.
Source: amazon-inspector (cdd4a17504623add1ff4f374ea9c2283d1eb5a863265e012592142b169cd9d90)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.