Logo
pypi

bloxypy@0.1.9

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 5:45 PM UTC

Malicious

OSV ID

MAL-2025-47572

Ecosystem

pypi

Summary

Attempting to use the module starts obfuscated code containing an infostealer --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-09-bloxypy Reasons (based on the campaign): - infostealer - obfuscation - action-hidden-in-lib-usage - infostealer:kiwi - exfiltration-browser-data

Source: kam193 (ca1bb0aab09d6ef59ee1ff8485c8c2a6b565c1311246ed61d63c9757bd44ecdc)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.