pypi

logghelper @1.0.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 11:32 AM UTC

Malicious

OSV ID

MAL-2025-6538

Ecosystem

pypi

Summary

Code attempts to download and run malware, as well as keeps ability to execute files sent via Telegram C2 channel --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-07-logghelper Reasons (based on the campaign): - malware - infostealer - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk.

Source: kam193 (2a5f0848002e1727d885bdf20c39e4949fd9609a4df5164a8c42ccc870aa6736)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.