Skip to main content

DEPENDENCY CONFUSION POC v0.0.2 — PoC with callback. Claimed to demonstrate the attack surface in Apple's ml-health-query-profiles.

This project has been quarantined.

PyPI Admins need to review this project before it can be restored. While in quarantine, the project is not installable by clients, and cannot be being modified by its maintainers.

Read more in the project in quarantine help article.

Project description

query-profile

⚠️ DEPENDENCY CONFUSION PROOF OF CONCEPT ⚠️

This package name (query-profile) was identified as unclaimed on PyPI while being directly referenced in Apple's official open-source repository:

This package is a harmless proof of concept — it does nothing except demonstrate that the package name was unclaimed and could be registered by an attacker. In a real attack, a malicious package under this name could:

  • Steal OpenAI/Anthropic/Azure API keys
  • Exfiltrate sensitive health query data
  • Install backdoors or persistence mechanisms

This package was published for responsible disclosure purposes only. No malicious code is included.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

query_profile-0.0.2.tar.gz (3.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

query_profile-0.0.2-py3-none-any.whl (3.5 kB view details)

Uploaded Python 3

File details

Details for the file query_profile-0.0.2.tar.gz.

File metadata

  • Download URL: query_profile-0.0.2.tar.gz
  • Upload date:
  • Size: 3.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for query_profile-0.0.2.tar.gz
Algorithm Hash digest
SHA256 95e2982d0093ef35fb99bdeb0bed1d55729a69ea11b05497eaeeca458f46ef57
MD5 b2f01f09f2776ff20990fe282f567e41
BLAKE2b-256 0e7266700f368add70fa8201a89b6baa28fb482a682990cc97083f6ee7a8a2b4

See more details on using hashes here.

File details

Details for the file query_profile-0.0.2-py3-none-any.whl.

File metadata

  • Download URL: query_profile-0.0.2-py3-none-any.whl
  • Upload date:
  • Size: 3.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for query_profile-0.0.2-py3-none-any.whl
Algorithm Hash digest
SHA256 be29aa2e7aee6b72a41f451723442052179e982b4929c421fca58a0922c9b1b9
MD5 039132f6064c1440f5514cb162483626
BLAKE2b-256 d0e408b47c8d78a5ae0132baa9e1a4cac3e71fc28beb8d7d8b010c1f4a60aeea

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page