Logo
pypi

browser-run@0.3.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 12:44 PM UTC

Malicious

OSV ID

MAL-2025-191696

Ecosystem

pypi

Summary

Package uses the name as popular NPM package (https://www.npmjs.com/package/browser-run), but the only thing it does is adding a hardcoded public SSH key and then calling back. This may allow the threat actor to remotely access the machine. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-browser-run Reasons (based on the campaign): - backdoor - dependency-confusion - action-hidden-in-lib-usage

Source: kam193 (3b45aebce3647704ac54d30a38e86493e0246f9ea44131394f84628656ef00ed)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.