pypi

hardixx-code @1.0.5

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 12:32 PM UTC

Malicious

OSV ID

MAL-2026-812

Ecosystem

pypi

Summary

Version 1.0.2 introduced loading obfuscated code during importing the module. However, distributions uploaded to PyPI lack the necessary file storing the code. It may either be a packaging issue or the dangerous content is supposed to be delivered via another channel to selected targets. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-02-hardixx-code Reasons (based on the campaign): - obfuscation

Source: kam193 (c0eeb07f1a0f9149c6e22016d85bcc59e5d0bbbac9514fbef9a2ba0289bf75fe)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.