httpx-client @0.0.1
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 9:32 AM UTC
OSV ID
MAL-2025-3448
Ecosystem
pypi
Summary
Importing the module starts downloading and executing first a script, and then a widely identified malware Packages are used as dependencies in a GitHub project https://github.com/ToolParadiseDrako/Nuker-Tool-Paradise --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-httpx-client Reasons (based on the campaign): - Downloads and executes a remote executable. - Downloads and executes a remote malicious script. - malware
Source: kam193 (d26dbf9fa1035b8b1e189f67123ee22f506cd21c08e17c282176a716af9da033)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.