browser-run@0.3.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 12:44 PM UTC
OSV ID
MAL-2025-191696
Ecosystem
pypi
Summary
Package uses the name as popular NPM package (https://www.npmjs.com/package/browser-run), but the only thing it does is adding a hardcoded public SSH key and then calling back. This may allow the threat actor to remotely access the machine. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-browser-run Reasons (based on the campaign): - backdoor - dependency-confusion - action-hidden-in-lib-usage
Source: kam193 (3b45aebce3647704ac54d30a38e86493e0246f9ea44131394f84628656ef00ed)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.