pypi

kotanku @0.1.0

Vulnerability report · Last retrieved from osv.dev August 10, 2026 at 4:17 AM UTC

Malicious

OSV ID

MAL-2026-13667

Ecosystem

pypi

Summary

During import, the package exfiltrates cryptocurrency wallet files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-kotanku Reasons (based on the campaign): - exfiltration-crypto - uses-telegram-bot

Source: kam193 (2281ff1cf735f26084f13f5f3ef5e1d5f9faf8cf06254532e5ee6d27204f52d1)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.