pypi
Maliciousindex-forum@2.5.4
Vulnerability report · Last retrieved from osv.dev September 18, 2026 at 2:37 AM UTC
OSV ID
MAL-2026-16268
Ecosystem
pypi
Summary
The package hides code to exfiltrate specific files from the user's machine. The used file paths suggest it was intended to be used in a CTF-like environment. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-pyjstat-smooth Reasons (based on the campaign): - files-exfiltration - obfuscation - targetted-attack - clones-real-package
Source: kam193 (7561fd94425cdde34f5f9f3d20482a0da8680414d0f38e1e00fea419ce23cf66)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.