decapod-common @1.2.dev2
Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 9:15 PM UTC
OSV ID
MAL-2026-13386
Ecosystem
pypi
Summary
setup.py overrides the install command to collect the installer's hostname and resolved IP address via socket.gethostname()/gethostbyname() and POST them as JSON to a hardcoded webhook.site endpoint (https://webhook.site/f79bb373-481e-4116-b3d1-35005970b62f) before completing installation. The beacon fires automatically during pip install of the sdist. The package's own metadata describes it as a POC beacon; no legitimate functionality accompanies the network callout.
Source: amazon-inspector (e0de84c80d520754e010d02b90fd4dc728d90fa9efe8c1e8cc6ddd7eb05e0da4)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.