cubesat-upstream-driver @1.0.1
Vulnerability report · Last retrieved from osv.dev August 9, 2026 at 6:16 PM UTC
OSV ID
MAL-2026-13666
Ecosystem
pypi
Summary
Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that. Originally detected by Aikido. --- Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2026-08-cubesat-upstream-driver Reasons (based on the campaign): - dependency-confusion - other
Source: kam193 (d669fdf7584f17d952cec3ed432bdb8f07672b43c3bc42ae68aa2d042d51481b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.