Logo
pypi

colourfulls@1.0.0

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC

Malicious

OSV ID

MAL-2024-12246

Ecosystem

pypi

Summary

Once imported, the module attempts to download an executable, put into Discord directory and most probably trick discord to start it. The download link does not work any more, so it's not possible to say what exactly the remote file did. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-08-old-colourfulls Reasons (based on the campaign): - Downloads and executes a remote executable. - typosquatting

Source: kam193 (735ca3ff38b76e7b11c1f7b884880871427299042e250bb42e17dcf66b8c8e11)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.