DEPENDENCY CONFUSION POC v0.0.2 — PoC with callback. Claimed to demonstrate the attack surface in Apple's ml-health-query-profiles.
This project has been quarantined.
PyPI Admins need to review this project before it can be restored. While in quarantine, the project is not installable by clients, and cannot be being modified by its maintainers.
Read more in the project in quarantine help article.
Project description
query-profile
⚠️ DEPENDENCY CONFUSION PROOF OF CONCEPT ⚠️
This package name (query-profile) was identified as unclaimed on PyPI while being directly referenced in Apple's official open-source repository:
- Repository: apple/ml-health-query-profiles
- Affected file: docs/TUTORIAL.md
- Issue: The tutorial instructs users to run
pip install query-profile, but Apple never published this package to PyPI.
This package is a harmless proof of concept — it does nothing except demonstrate that the package name was unclaimed and could be registered by an attacker. In a real attack, a malicious package under this name could:
- Steal OpenAI/Anthropic/Azure API keys
- Exfiltrate sensitive health query data
- Install backdoors or persistence mechanisms
This package was published for responsible disclosure purposes only. No malicious code is included.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file query_profile-0.0.2.tar.gz.
File metadata
- Download URL: query_profile-0.0.2.tar.gz
- Upload date:
- Size: 3.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
95e2982d0093ef35fb99bdeb0bed1d55729a69ea11b05497eaeeca458f46ef57
|
|
| MD5 |
b2f01f09f2776ff20990fe282f567e41
|
|
| BLAKE2b-256 |
0e7266700f368add70fa8201a89b6baa28fb482a682990cc97083f6ee7a8a2b4
|
File details
Details for the file query_profile-0.0.2-py3-none-any.whl.
File metadata
- Download URL: query_profile-0.0.2-py3-none-any.whl
- Upload date:
- Size: 3.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.2.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
be29aa2e7aee6b72a41f451723442052179e982b4929c421fca58a0922c9b1b9
|
|
| MD5 |
039132f6064c1440f5514cb162483626
|
|
| BLAKE2b-256 |
d0e408b47c8d78a5ae0132baa9e1a4cac3e71fc28beb8d7d8b010c1f4a60aeea
|