Flagged as malicious
- malware, affects all versions
cvss9.0
how bad it is if exploited, out of 10
epssnot scored
chance of exploitation in the next 30 days
xyz score4.0
CyberXYZ composite, out of 10
fig. 01 — GHSA-v95x-h953-x7fg, the advisory selected below
// advisories
GHSA-v95x-h953-x7fg
CRITICALThis package contained malicious code. The package uploaded system information such as OS and hostname to a remote server.
- Affected
- >= 0.0.0, >=0.0.0
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2020-09-03
- Source
- github
GHSAreference
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.
Checked 2026-09-22 at 02:40 UTC. The most recent advisory here was published 2020-09-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.