auohttp @3.13.3
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 2:32 PM UTC
OSV ID
MAL-2026-38
Ecosystem
pypi
Summary
Obfuscated code downloads an encrypted binary blob, which is malware finally starting cryptomining. After starting the malware, the Python package uninstall itself and installs the legitimate package, covering tracks of the infection. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-01-aiihttp Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - malware - cryptominer - obfuscation - covering-tracks
Source: kam193 (f4b76a407d91e23cb990d6ed08e3c0e81898f2b97d690db76b4e3b547fda5fab)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.