pypi
Malicious giteegit @1.0.5
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 1:32 PM UTC
OSV ID
MAL-2025-191739
Ecosystem
pypi
Summary
Package exfiltrates source code files to a telegram channel, while the description promises saving them to a git service --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-giteegit Reasons (based on the campaign): - files-exfiltration - A Telegram webhook is used to send collected data.
Source: kam193 (4a26c5d911f4394086eca9dfca0dfb8b05cc0675bac36dfdbec08e30f6d1abed)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.