Skip to main content

DEPENDENCY CONFUSION POC — This package name was unclaimed on PyPI. Claimed by security researcher to demonstrate the attack surface in Apple's ml-health-query-profiles repository.

This project has been quarantined.

PyPI Admins need to review this project before it can be restored. While in quarantine, the project is not installable by clients, and cannot be being modified by its maintainers.

Read more in the project in quarantine help article.

Project description

query-profile

⚠️ DEPENDENCY CONFUSION PROOF OF CONCEPT ⚠️

This package name (query-profile) was identified as unclaimed on PyPI while being directly referenced in Apple's official open-source repository:

This package is a harmless proof of concept — it does nothing except demonstrate that the package name was unclaimed and could be registered by an attacker. In a real attack, a malicious package under this name could:

  • Steal OpenAI/Anthropic/Azure API keys
  • Exfiltrate sensitive health query data
  • Install backdoors or persistence mechanisms

This package was published for responsible disclosure purposes only. No malicious code is included.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

query_profile-0.0.1.tar.gz (2.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

query_profile-0.0.1-py3-none-any.whl (2.3 kB view details)

Uploaded Python 3

File details

Details for the file query_profile-0.0.1.tar.gz.

File metadata

  • Download URL: query_profile-0.0.1.tar.gz
  • Upload date:
  • Size: 2.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for query_profile-0.0.1.tar.gz
Algorithm Hash digest
SHA256 4155304e57e706ebce3761edf51837b6a4cd07183643c4ce137b8a7441fa4392
MD5 40ac99644160158e35253276674b08b2
BLAKE2b-256 740aa3fe2199be19c0a739f67c0047c2417ff66c94ff0609855920f1d8ef6cb5

See more details on using hashes here.

File details

Details for the file query_profile-0.0.1-py3-none-any.whl.

File metadata

  • Download URL: query_profile-0.0.1-py3-none-any.whl
  • Upload date:
  • Size: 2.3 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for query_profile-0.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 10544c1fc884d3196be616a8299482a90360d2baa552a9a7325ef447deb8a86a
MD5 f336ddb264266abf09df92eec57543f3
BLAKE2b-256 6c07c2e44cf77743ce0470be124a619d27cfa08877f4cbf241bf65e1a411ce90

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page