foundry-jupyter-extension@800.23.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:42 AM UTC
OSV ID
MAL-2025-6248
Ecosystem
pypi
Summary
Installing or importing the module triggers exfiltration of environmental variables --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-foundry-jupyter-extension Reasons (based on the campaign): - exfiltration-env-variables - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - The package overrides the install command in setup.py to execute malicious code during installation.
Source: kam193 (8114162af3676e6c75f96e1dc953dae363e41fab4e9b3ce75a84b261aece0113)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.