pypi

aliyun-python-sdk-v2 @2.13.36

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 10:35 AM UTC

Malicious

OSV ID

MAL-2026-917

Ecosystem

pypi

Summary

Series of packages impersonating Alibaba Cloud. Two oldest hide code to run obfuscated code, but are likely to be used as dependency as the obfuscated code is not inside. The newest describe similar functionality, but the inside is highly obfuscated. Package names closely reassemble names of real Alibaba packages --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-alibabacloude Reasons (based on the campaign): - typosquatting - impersonation - obfuscation

Source: kam193 (29bd2455a576643c51939bd166abab847afd04c3142b576e3f9f0c7978763181)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.