pypi

alpha-booster @1.3

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 4:36 PM UTC

Malicious

OSV ID

MAL-2025-6431

Ecosystem

pypi

Summary

Code downloads and runs the remote executable. While the current link seems not to work, the previous versions had an embedded infostealer instead. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-05-discord-booster Reasons (based on the campaign): - infostealer - Downloads and executes a remote executable.

Source: kam193 (8fe7614b282cfa81278bc61bde1998e286fe7554c1d37b4c3185718c6e54f6af)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.