logo

Database

Use of software with malware In horde-python-client

Description

horde-python-client 99999.0.0 is a dependency-confusion lure. On import horde_python_client, a daemon thread unconditionally POSTs a JSON payload containing the host's hostname, the USER/USERNAME environment variable, and the current working directory to http://109.123.247.172/pypi over plain HTTP. The destination is a bare IP unrelated to any legitimate package publisher. The package ships with placeholder metadata (description "Internal package", author "Security Research") and an absurdly high version number (99999.0.0) — the canonical shape for overriding a target organization's private package of the same name in resolver precedence. Installer harm: any developer or build system that resolves this package and imports it leaks host identifiers to the attacker, confirming a successful dependency-confusion hit and enabling follow-on targeting.

Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version