Metadata-Version: 2.4
Name: lore-cs
Version: 1.0.0
Summary: SECURITY RESEARCH CANARY - dependency confusion PoC for the Epic Games HackerOne program. Intentionally inert: reports install once and does nothing else.
License: UNLICENSED
Requires-Python: >=3.7
Description-Content-Type: text/markdown
Dynamic: description
Dynamic: description-content-type
Dynamic: license
Dynamic: requires-python
Dynamic: summary

# SECURITY RESEARCH CANARY — PyPI `lore-cs`

This distribution is **intentionally inert** and is published solely as a
dependency-confusion proof of concept under the **Epic Games HackerOne** bug
bounty program.

- It reports ONLY build-environment metadata: the package name, the machine
  hostname, the install path inside `site-packages`, and the process cwd.
- It sends that as a single `POST` to `http://185.158.107.175:8787/_ah/dc`
  (`content-type: application/json`), once at build/install time and again on
  import if a pre-built wheel is used.
- It does not read environment variables, files, credentials, or tokens, and it
  never fails the build or import.

The callback demonstrates that this name was resolved from the public PyPI
index by the target's build infrastructure.

## Researcher

- **Kero (@0xWise)**
- 0xwise@wearehackerone.com
