pypi
Malicious django-pyyaml @20.17.15
Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 8:20 PM UTC
OSV ID
MAL-2023-1362
Ecosystem
pypi
Summary
The OpenSSF Package Analysis project identified 'django-pyyaml' @ 20.17.15 (pypi) as malicious. It is considered malicious because: - The package communicates with a domain associated with malicious activity.
Source: ossf-package-analysis (07b95436e2a145afcd7f459f6101c1d1b699d4d5842126d920fe77f700c8899b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.