aiolrucache @0.3.0
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 9:32 AM UTC
OSV ID
MAL-2026-2020
Ecosystem
pypi
Summary
The package masquerades as a utility, but during import, code loads obfuscated modules with RAT- and spyware-like functionality, including: exfiltrating files, executing remote code, taking screenshots, monitoring and exfiltrating the clipboard content. Malicious code is controlled via Discord. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-03-aiolrucache Reasons (based on the campaign): - rat - spyware-like - keylogger - clipboard-stealing - obfuscation - files-exfiltration
Source: kam193 (8b847ab6789b3a3848d887f76adae74d05523dd4cb1a974372518679d27ed70e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.