Logo
pypi

conn-utils@1.6.11

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC

Malicious

OSV ID

MAL-2025-191706

Ecosystem

pypi

Summary

Already during the installation, the file with slightly obfuscated code is loaded and starts exfiltrating information about the host. It especially targets information about additional indexes configured for pip. Data is exfiltrated using DNS queries --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-conn-utils Reasons (based on the campaign): - exfiltration-generic - obfuscation

Source: kam193 (25be0eaa51dd4c4ba03afd81b4cfad938ceb07dacb0195a9179b46413178e086)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.