Logo
pypi

aitextkit-py@0.1.1

Vulnerability report · Last retrieved from osv.dev September 11, 2026 at 8:19 PM UTC

Malicious

OSV ID

MAL-2026-16130

Ecosystem

pypi

Summary

The package hides code downloading script, which then downloads and executes a heavily obfuscated final stage. The remote stages are hosted on a domain presenting a suspicious-looking corporate website. The downloaded code establishes persistence e.g. as "anymeetly-cameradriver" systemd service. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-aitextkit-py Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - persistence

Source: kam193 (b1a048ec587dcab5a71ed9423d105b4b972f646b93f790f62c10d394610b64bf)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.