pypi

dev-helper-bg @0.1.7

Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC

Malicious

OSV ID

MAL-2026-10992

Ecosystem

pypi

Summary

The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-make-helper Reasons (based on the campaign): - files-exfiltration - obfuscation - uses-telegram-bot

Source: kam193 (9466ff28252daa546dc9a75b6b255e94dc6a6409d69197b40b573d05d002d340)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.