colourfulls@1.0.0
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC
OSV ID
MAL-2024-12246
Ecosystem
pypi
Summary
Once imported, the module attempts to download an executable, put into Discord directory and most probably trick discord to start it. The download link does not work any more, so it's not possible to say what exactly the remote file did. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-old-colourfulls Reasons (based on the campaign): - Downloads and executes a remote executable. - typosquatting
Source: kam193 (735ca3ff38b76e7b11c1f7b884880871427299042e250bb42e17dcf66b8c8e11)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.