Logo
pypi

chroma-client@0.5.7

Vulnerability report · Last retrieved from osv.dev September 14, 2026 at 4:21 AM UTC

Malicious

OSV ID

MAL-2026-16143

Ecosystem

pypi

Summary

This package does not carry any malicious payload yet, but uses exactly the same technique as other packages from the campaign aiming to mislead LLM security tools. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-openaii Reasons (based on the campaign): - Downloads and executes a remote malicious script. - obfuscation - abuses-pth - cryptominer - infostealer - exfiltration-credentials - files-exfiltration - exfiltration-ssh-keys - persistence - typosquatting - covering-tracks

Source: kam193 (f74658ebb12f3a5cbf8577a768965f3ae81fbe8a156acc843ecffe3dfe2e5153)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.