pypi

learning-pypi-demo-nisimi @0.1.5

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 11:32 AM UTC

Malicious

OSV ID

MAL-2025-47782

Ecosystem

pypi

Summary

Installing packages exfiltrates data (different in different packages and versions) or run revshells --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-08-learning-pypi-demo-nisimi Reasons (based on the campaign): - The package contains code to create a reverse shell, allowing an attacker to execute any commands on the victim's machine. - exfiltration-generic

Source: kam193 (0b3a0d62b36ae3a2e643a327b7cf5b88366d4a8a89381eca570f34c453f1eaf4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.