pypi

deepface-weight @0.1.4

Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC

Malicious

OSV ID

MAL-2026-14158

Ecosystem

pypi

Summary

On import, deepface-weight spawns a daemon background thread that polls the installer's working directory for data/telethon_market_userbot.session for approximately 10 minutes and POSTs the file to a hardcoded webhook.site endpoint (https://webhook.site/d6ea9c5b-4a85-4e59-9397-2bb5f9407c87). Telethon session files contain live authentication material granting full access to the associated Telegram account. The exfiltration destination is bound to a variable literally named evil_server_url with a Russian-language comment identifying it as the attacker's server. The package name mimics the popular deepface ML library but ships no machine-learning code; author metadata is a placeholder ( asdqwdasdqwdasd ) with a disposable email at playboot.com.

Source: amazon-inspector (6808b9ae619e6cf9fdb59b52305e25b8e2fdb87167fbd78fae0ca6c1c07a5f1a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.