pypi

kertash @0.1.5

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 11:32 AM UTC

Malicious

OSV ID

MAL-2025-191774

Ecosystem

pypi

Summary

When using methods from the package, it downloads an obfuscated code from Github and puts it in multiple localisation. While it appears that this code is used to perform action user requested, deobfuscation reveals exfiltrating user's data instead. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-kertash Reasons (based on the campaign): - exfiltration-generic - A Telegram webhook is used to send collected data. - obfuscation - action-hidden-in-lib-usage

Source: kam193 (3cb3ef6da7e0d1c1461bb944c5ff0e356b73e52d271afa9e94435097f1d0764f)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.