pypi

cubesat-upstream-driver @1.0.1

Vulnerability report · Last retrieved from osv.dev August 9, 2026 at 6:16 PM UTC

Malicious

OSV ID

MAL-2026-13666

Ecosystem

pypi

Summary

Package appears to abuse PyPI for a CTF-like exercise. It can collect up to all environment variables. The package does not exfiltrate them on its own, suggesting there is another external trigger for that. Originally detected by Aikido. --- Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities. Campaign: 2026-08-cubesat-upstream-driver Reasons (based on the campaign): - dependency-confusion - other

Source: kam193 (d669fdf7584f17d952cec3ed432bdb8f07672b43c3bc42ae68aa2d042d51481b)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.