pypi
Maliciouscolorinal@0.1.7
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 10:42 AM UTC
OSV ID
MAL-2025-47451
Ecosystem
pypi
Summary
This package is malicious and allows an attack remote code execution on Windows and Linux machines. The package termncolor uses colorinal as a dependency. The package colorinal contains the malicious behavior.
Source: google-open-source-security (aac66e0b739a7c06226108da151ee90cc6b406fcf287093e3ca4da4f5eebf79e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.