pypi

govapkg @0.1.0

Vulnerability report · Last retrieved from osv.dev July 24, 2026 at 12:21 AM UTC

Malicious

OSV ID

MAL-2026-11031

Ecosystem

pypi

Summary

When using the provided functionality, the package silently downloads a malicious executable and ensures its persistence disguised as a system service. The binary connects with telegra[.]ph. It appears that the contacted URL is built from the template https://api.telegra.ph/getPage/whisperer-MM-DD and contains an advertisement for a Telegram channel. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-govpkg Reasons (based on the campaign): - Downloads and executes a remote executable. - action-hidden-in-lib-usage - persistence

Source: kam193 (c23fe2f960316aca782b4319dac6f960d4397ec40428d34e28b1769cd0bff4b4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.