pypi
Malicious decoris @0.3.3
Vulnerability report · Last retrieved from osv.dev August 27, 2026 at 3:26 PM UTC
OSV ID
MAL-2026-14554
Ecosystem
pypi
Summary
The package exfiltrates Roblox cookies from the victim machine. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-spaysrbdata Reasons (based on the campaign): - infostealer
Source: kam193 (1ce74b34855100b6ba312f767a982fb288a802da613fec375aec92665f4d9973)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.