pypi
Malicioushahabott@1.29.3
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 11:44 AM UTC
OSV ID
MAL-2025-191746
Ecosystem
pypi
Summary
If run as module, it attempts to automatically destroy user's and system's files. Some versions also exfiltrate them. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-hahabott Reasons (based on the campaign): - files-exfiltration - destructive-actions
Source: kam193 (89ed03d9e80d4ef62c54087a12177f795e478b1b5e5a8af69ef4e4740e102186)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.