pypi package report

Is plugin-scanner safe?

Confirmed malicious. Do not install it, and remove it where it has been installed.

Do not install this package

CRITICAL

Sandbox observed install-time exfil (cross-signal auto). Confirmed 2026-09-22, CyberXYZ cross-signal detection, automatic.

// what we observed
  • package contents+8

    environment-variable read (corroborating; no exfil co-signal)

  • package contents+10

    pickle deserialize of untrusted data

  • package contents+8

    source finding (sev 10)

  • package contents+15

    novel source finding (sev 10)

  • package contents+2

    test-context finding (sev 9)

  • package contents+2

    test-context finding (sev 10)

  • install sandbox+35

    install-phase read of sensitive path

  • reputation-15

    popular package (1185 versions over 125d) with pattern-only evidence — de-escalated for review rather than blocked

// versions and what to do
Malicious
3.0.0a235
Clean
none confirmed

Remove it from every machine and lockfile it reached. Treat any credentials, tokens and SSH keys present on those machines as exposed and rotate them. Check CI runners and container images that installed it.

pip uninstall plugin-scanner
// reach

22 direct dependencies

10 carry known advisories, worst CRITICAL

0 packages depend on it

an advisory here reaches each of them

    Create a free accountfor every dependency path, dependent and what to upgrade
    // ai model usage

    No published models are known to use this package.



    Checked 2026-09-22 at 21:09 UTC. Updated continuously from NVD, GHSA, OSV and CNA feeds.

    Think a verdict here is wrong? Tell us — we respond within 2 business days.
    Is plugin-scanner safe? pypi package security report | CyberXYZ