🚀 Socket Launch Week Day 5:Introducing Repository Access Permissions and Custom Roles.Learn more
Sign In

query-profile

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install
Malicious code was recently detected in this package.

Affected versions:

0.0.10.0.20.0.3

query-profile

DEPENDENCY CONFUSION POC v0.0.3 — PoC with Burp Collaborator callback. Claimed by L0bo to demonstrate attack surface in Apple's ml-health-query-profiles.

pipPyPI
Version
0.0.3
Weekly downloads
227
Maintainers
1

query-profile

⚠️ DEPENDENCY CONFUSION PROOF OF CONCEPT ⚠️

This package name (query-profile) was identified as unclaimed on PyPI while being directly referenced in Apple's official open-source repository:

  • Repository: apple/ml-health-query-profiles
  • Affected file: docs/TUTORIAL.md
  • Issue: The tutorial instructs users to run pip install query-profile, but Apple never published this package to PyPI.

This package is a harmless proof of concept — it does nothing except demonstrate that the package name was unclaimed and could be registered by an attacker. In a real attack, a malicious package under this name could:

  • Steal OpenAI/Anthropic/Azure API keys
  • Exfiltrate sensitive health query data
  • Install backdoors or persistence mechanisms

This package was published for responsible disclosure purposes only. No malicious code is included.

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts