Encyclopedia
PyPI⚠ HIGHslopsquat⚠ ACTIVE THREAT

opencv-python-headless-utils

First seen: Jan 12, 2025 0 viewsMimics: opencv-python-headless
Share threatHN
Threat Description

Hallucinated utility layer for opencv-python-headless. The registered version bundles a cryptominer in a native extension that activates only when running as root, targeting containerized CI environments.

AI Hallucination Analysis
Very Likely AI Hallucination86%
Known to be hallucinated by: ChatGPT-4, Copilot
Remediation Guide
  1. Remove 'opencv-python-headless-utils' from your dependencies immediately.
  2. Replace with the legitimate package 'opencv-python-headless'.
  3. Audit CI/CD containers for cryptomining artifacts.
  4. Rotate any exposed secrets.
Quick Facts
Ecosystem
PyPI
Risk Level
HIGH
Type
slopsquat
Status
ACTIVE
Legitimate Package
opencv-python-headless
Hallucination Confidence
86%
Check My Project
Scan for this package