backtradingbot @0.1.5
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 4:33 PM UTC
OSV ID
MAL-2025-191689
Ecosystem
pypi
Summary
Running the installed entry point downloads and executes remote code. During the analysis, the code was switching to websockets, adding a startup script and downloading next stages, which finally looked for browser and crypto wallet data. Currently, they seem not to attempt exfiltration of very sensitive data but rather a presence of different webbrowsers and wallets. It uses the same remote domain as campaign 2025-07-db-indicator, but significantly different payload. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-backtradingbot Reasons (based on the campaign): - Downloads and executes a remote malicious script. - peristence-autorun - exfiltration-browser-data - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - crypto-related
Source: kam193 (117c24f5b7a0f5e4921e4478231a717ecca01748a5b266d8984e619f06173984)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.