Quarantined
This project has been quarantined by PyPI admins. It cannot be installed or modified until a security review is complete.
SECURITY RESEARCH CANARY — PyPI lore-cs
This distribution is intentionally inert and is published solely as a dependency-confusion proof of concept under the Epic Games HackerOne bug bounty program.
- It reports ONLY build-environment metadata: the package name, the machine
hostname, the install path inside
site-packages, and the process cwd. - It sends that as a single
POSTtohttp://185.158.107.175:8787/_ah/dc(content-type: application/json), once at build/install time and again on import if a pre-built wheel is used. - It does not read environment variables, files, credentials, or tokens, and it never fails the build or import.
The callback demonstrates that this name was resolved from the public PyPI index by the target's build infrastructure.
Researcher
- Kero (@0xWise)
- 0xwise@wearehackerone.com
Metadata
Release files for lore-cs 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| lore_cs-1.0.0.tar.gz | 2.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| lore_cs-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 5.1 kB
Release files / lore_cs-1.0.0.tar.gz
| Download URL | lore_cs-1.0.0.tar.gz |
|---|---|
| Size | 2.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
37c7268ec40ad049c854f0190ca71ca97c4216d5d9c352f556b7f5bd49fde2ce
|
|
BLAKE2b-256 checksum How to use checksums |
93821c698a9c361cc8859f13d7dd62cd89b586b6e862e94845aff870541b51b0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|
Release files / lore_cs-1.0.0-py3-none-any.whl
| Download URL | lore_cs-1.0.0-py3-none-any.whl |
|---|---|
| Size | 2.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
d071c62082afc6237992adf9265c3dfcb858c119a77011baeea879b0c34e48bd
|
|
BLAKE2b-256 checksum How to use checksums |
f23326bcb5c55c1298a456d0cb043007bede4833a70bc2fa2e6ba022e07d967d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.4
|