kafka-roller@99.0.6
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:46 PM UTC
OSV ID
MAL-2026-17703
Ecosystem
pypi
Summary
setup.py starts a background thread at module load (fires on pip install and sdist build) that collects host identifiers — hostname, current working directory, platform, timestamp, and a generated uuid — and transmits them to the hardcoded subdomain db3va6lrl89cd975pn4078o6efah78yct.oast.live, both over HTTPS and via DNS lookups spawned through nslookup, getent hosts, and dig +short against a dynamically-constructed hostname under the same OAST domain. The DNS path provides a side-channel that bypasses HTTP egress filtering. Package metadata labels the project kafka_roller, pins version 99.0.0, and points url at github.com/teslamotors/kafka-helmsman with a description reserving the name for Tesla — the dependency-confusion shape designed to win resolution over an internal package of the same name on any build machine configured to resolve from public PyPI. A comment framing the beacon as security research does not change the behavior: installer host identifiers leave to an attacker-controlled collector on every install of this public name, not only on the claimed target's infrastructure.
Source: amazon-inspector (1ef3d9dc9185cea1ba30aafd4daa80e2a5b1a5dcf1bc59a4a5a5fbae9a480b17)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.