
Security News
/Research
Fake Corepack Site Distributes Infostealer and Proxyware to Developers
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
blessclient
Advanced tools
This is NOT the real Lyft blessclient tool. This package is an inert
canary published as part of authorized security research (a Lyft
HackerOne bug-bounty engagement) to test for a dependency-confusion
condition: the name blessclient was unclaimed on PyPI while being the exact
package name declared in Lyft's public github.com/lyft/python-blessclient
repository.
Nothing harmful. On install it makes a single HTTP GET to a Canarytokens URL so the researcher is notified that some machine installed the name from the public index. It collects only what that request naturally exposes (source IP / user-agent). It contains no payload, no data exfiltration, no code execution beyond the notification ping, and no functionality. It intentionally does not implement any SSH-certificate behaviour.
This confirms your build or developer tooling can resolve blessclient from the
public PyPI index. The fix is to (a) claim the blessclient name on PyPI under
Lyft ownership, and/or (b) pin your internal index / use --index-url scoping so
public-index fallback cannot occur. Please contact the researcher via the Lyft
HackerOne program. This package will be removed / handed over on request.
Reported through the Lyft HackerOne program. Researcher alias:
7amzar@wearehackerone.com.
Version 0.0.1 is deliberately below any version anyone would intentionally
depend on.
FAQs
Test package
The pypi package blessclient receives a total of 0 weekly downloads. As such, blessclient popularity was classified as not popular.
We found that blessclient demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
/Research
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.

Research
/Security News
A large-scale campaign abused GitHub Actions in compromised repositories to exploit CVE-2026-41940 in cPanel and WHM and steal server credentials.

Security News
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.