Confirmed malicious. Do not install it, and remove it where it has been installed.
Sandbox observed install-time exfil (cross-signal auto). Confirmed 2026-09-22, CyberXYZ cross-signal detection, automatic.
pickle deserialize of untrusted data
environment-variable read (corroborating; no exfil co-signal)
source finding (sev 10)
novel source finding (sev 10)
install-phase read of sensitive path
popular package (14,321 weekly downloads; 1681 versions over 125d) with pattern-only evidence — de-escalated for review rather than blocked
Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.
pip uninstall hol-guard
0 packages depend on it
an advisory here reaches each of them
No published models are known to use this package.
Checked 2026-09-22 at 21:10 UTC. Updated continuously from NVD, GHSA, OSV and CNA feeds.