pypi

logax @8.3

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 11:32 AM UTC

Malicious

OSV ID

MAL-2025-3450

Ecosystem

pypi

Summary

The package is capable of installing malware from a hardcoded URL. The malware is well-recognized and acts as infostealer. Interestingly, it uses Steam profiles to get the current C2 domain (based on sandbox analysis). --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-03-logax Reasons (based on the campaign): - infostealer - malware

Source: kam193 (e129e6d6d38e21a039bd2190e3138f1381ad386e45a49521621a8b8ad61f7678)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.