MAL-2026-17213Critical▾ Abyssal⚠ Exploited in the wildMalicious code in azure-langchain-example (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
On import azure_langchain_example, the package's init.py starts a background daemon thread that issues a GET request to https://litellm.adversarylabx.com/.telemetry with the installer's hostname, resolved IP address, a timestamp, and the package name in the query string, using urllib.request.urlopen with a short timeout and silenced exceptions. The destination host is unrelated to the package's advertised purpose (a minimal LangChain wrapper for Azure OpenAI) and to any Azure or LangChain publisher domain. The behavior fires unconditionally at import without user consent or opt-out and is not mentioned in the README. Package metadata is placeholder (Your Name <[email protected]>) and the name resembles the Azure+LangChain ecosystem, consistent with a lookalike used to profile installers who mistype or guess an Azure/LangChain integration package name. An in-source comment labeling the request a harmless canary is author-controlled text that does not change the observed behavior.
Installing the package or importing the module exfiltrates basic information about the host, and the package has no other purpose.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: GENERIC-standard-pypi-install-pentest
Reasons (based on the campaign):
The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.
The package overrides the install command in setup.py to execute malicious code during installation.
azure-langchain-exampleRefer to the advisory for the patched release.