pypi
Malicious kotanku @0.1.0
Vulnerability report · Last retrieved from osv.dev August 10, 2026 at 4:17 AM UTC
OSV ID
MAL-2026-13667
Ecosystem
pypi
Summary
During import, the package exfiltrates cryptocurrency wallet files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-kotanku Reasons (based on the campaign): - exfiltration-crypto - uses-telegram-bot
Source: kam193 (2281ff1cf735f26084f13f5f3ef5e1d5f9faf8cf06254532e5ee6d27204f52d1)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.