pypi

decapod-common @1.2.dev2

Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 9:15 PM UTC

Malicious

OSV ID

MAL-2026-13386

Ecosystem

pypi

Summary

setup.py overrides the install command to collect the installer's hostname and resolved IP address via socket.gethostname()/gethostbyname() and POST them as JSON to a hardcoded webhook.site endpoint (https://webhook.site/f79bb373-481e-4116-b3d1-35005970b62f) before completing installation. The beacon fires automatically during pip install of the sdist. The package's own metadata describes it as a POC beacon; no legitimate functionality accompanies the network callout.

Source: amazon-inspector (e0de84c80d520754e010d02b90fd4dc728d90fa9efe8c1e8cc6ddd7eb05e0da4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.