Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ MAL-2026-4753 — gt-tester-exp-profiler-exp-00000017

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Malicious code in gt-tester-exp-profiler-exp-00000017 (PyPI)

Source: amazon-inspector

setup.py installs a site-wide.pth file (gt_tester_exp_profiler_exp_00000017_probe.pth) into site-packages that imports the package's probe module and calls run_probe() at every Python interpreter startup. probe.py performs a plaintext HTTP GET to the bare IP 104.236.116.157 with a per-call random hex tag, fingerprinting the installer's machine to a third party on every Python invocation — not just when the package is explicitly imported. The User-Agent string claims an 'Academic research study' but no consent is obtained at install or runtime. Package metadata is a generic placeholder with no author, homepage, or publisher identification, and the destination is a bare IP not associated with any declared publisher. The.pth mechanism converts what would be an import-time call into persistent host beaconing across every CI job, virtualenv activation, and script execution on the machine.

Affected software

MAL-2026-4753 is recorded against 1 package.

  • gt-tester-exp-profiler-exp-00000017

Timeline and source

Published on 22 May 2026 and last revised on 26 May 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

pypi.org (Package)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-05-22
Updated 2026-08-20
Modified 2026-05-26
Fix URL N/A

Affected Packages

Software From version Fixed in
gt-tester-exp-profiler-exp-00000017

Free Vulnerability Check

Is your site affected by MAL-2026-4753?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MAL-2026-4753 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesMalicious packagesMalicious packages 2026