deepface-weights @0.1.2
Vulnerability report · Last retrieved from osv.dev August 19, 2026 at 3:49 AM UTC
OSV ID
MAL-2026-14132
Ecosystem
pypi
Summary
On import, deepface_weights starts a daemon thread that polls every 10 seconds for the file data/telethon_market_userbot.session in the current working directory. When found, it POSTs the session file together with the local os.getlogin() value to the hardcoded endpoint https://webhook.site/730d2d03-5c78-4e0a-88df-9d8466b7e8aa. A Telethon .session file holds authenticated Telegram credentials, so exfiltration enables full takeover of the associated Telegram account. Package metadata is placeholder (author email rozuvu@example.com , description Minimal example Python package ) and the name resembles the unrelated deepface face-recognition library, but the package ships none of that functionality — the stealer is its only behavior. Source comments in Russian label the destination as the attacker's server.
Source: amazon-inspector (9c1cf8a0f273b75a4cf2b66c9b9fc351023b9f77d61e82c74d74534424ce0558)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.