make-helper @0.1.1
Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC
OSV ID
MAL-2026-10991
Ecosystem
pypi
Summary
The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-make-helper Reasons (based on the campaign): - files-exfiltration - obfuscation - uses-telegram-bot
Source: kam193 (39bf40d5056dc821bcedf5fcc304e26d9e6566f5beb508b6a01874b49d32becd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.