pypi

aiohtto @3.13.3

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC

Malicious

OSV ID

MAL-2026-36

Ecosystem

pypi

Summary

Obfuscated code downloads an encrypted binary blob, which is malware finally starting cryptomining. After starting the malware, the Python package uninstall itself and installs the legitimate package, covering tracks of the infection. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-01-aiihttp Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - malware - cryptominer - obfuscation - covering-tracks

Source: kam193 (9338a4f3f167cf0ba279696ac9ae9bae26219391e2a87a805cc8bb92b4cddd6e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.