aitextutils-py@0.1.1
Vulnerability report · Last retrieved from osv.dev September 11, 2026 at 8:19 PM UTC
OSV ID
MAL-2026-16131
Ecosystem
pypi
Summary
This package executes code from malicious dependency, which hides code downloading script, which then downloads and executes a heavily obfuscated final stage. The remote stages are hosted on a domain presenting a suspicious-looking corporate website. The downloaded code establishes persistence e.g. as "anymeetly-cameradriver" systemd service. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-aitextkit-py Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - persistence
Source: kam193 (079adf053b093075a5d8151dbbb82bb85a45f577ae3a9f6e6c751a4779d52f77)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.