pypi package report

Is hol-guard safe?

Confirmed malicious. Do not install it, and remove it where it has been installed.

Do not install this package

CRITICAL

Sandbox observed install-time exfil (cross-signal auto). Confirmed 2026-09-22, CyberXYZ cross-signal detection, automatic.

// what we observed
  • package contents+10

    pickle deserialize of untrusted data

  • package contents+8

    environment-variable read (corroborating; no exfil co-signal)

  • package contents+8

    source finding (sev 10)

  • package contents+15

    novel source finding (sev 10)

  • install sandbox+35

    install-phase read of sensitive path

  • reputation-15

    popular package (14,321 weekly downloads; 1681 versions over 125d) with pattern-only evidence — de-escalated for review rather than blocked

// versions and what to do
Malicious
3.0.0a235
Clean
none confirmed

Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.

pip uninstall hol-guard
// reach

26 direct dependencies

11 carry known advisories, worst CRITICAL

0 packages depend on it

an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    No published models are known to use this package.



    Checked 2026-09-22 at 21:10 UTC. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.
    Is hol-guard safe? pypi package security report | CyberXYZ