pypi
Malicious hxq-misc-utils-0379 @2026.315.2
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 10:32 AM UTC
OSV ID
MAL-2026-1453
Ecosystem
pypi
Summary
This package includes an encrypted payload file that appears to be used to deliver code or resources to other packages. The payload changes between releases, and because its contents cannot be inspected, it lacks transparency and violates PyPI’s publishing rules.
Source: oracle-using-macaron (1e22088fbe314143f0c3eb971a645a125a9a32753184ceb5abd533ac7e60da69)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.