chroma-client@0.5.7
Vulnerability report · Last retrieved from osv.dev September 14, 2026 at 4:21 AM UTC
OSV ID
MAL-2026-16143
Ecosystem
pypi
Summary
This package does not carry any malicious payload yet, but uses exactly the same technique as other packages from the campaign aiming to mislead LLM security tools. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-openaii Reasons (based on the campaign): - Downloads and executes a remote malicious script. - obfuscation - abuses-pth - cryptominer - infostealer - exfiltration-credentials - files-exfiltration - exfiltration-ssh-keys - persistence - typosquatting - covering-tracks
Source: kam193 (f74658ebb12f3a5cbf8577a768965f3ae81fbe8a156acc843ecffe3dfe2e5153)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.