A new package named 'ros2-http-gateway' was published to PyPI, providing a config-driven HTTP and Server-Sent Events (SSE) gateway for ROS 2 systems. The package introduces potential security risks due to lack of verification of its authenticity or security posture, potentially exposing ROS 2 deployments to unauthorized access or data exfiltration. Users who install this package may unknowingly introduce a new attack surface into their ROS 2 environments.