dev-helper-bg @0.1.7
Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC
OSV ID
MAL-2026-10992
Ecosystem
pypi
Summary
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-make-helper Reasons (based on the campaign): - files-exfiltration - obfuscation - uses-telegram-bot
Source: kam193 (9466ff28252daa546dc9a75b6b255e94dc6a6409d69197b40b573d05d002d340)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.