pypi

make-helper @0.1.1

Vulnerability report · Last retrieved from osv.dev July 23, 2026 at 9:18 AM UTC

Malicious

OSV ID

MAL-2026-10991

Ecosystem

pypi

Summary

The package embeds encrypted code that, during import, is decrypted using an externally sourced password. The recovered code is executed and starts a bot capable of exfiltrating local files. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-make-helper Reasons (based on the campaign): - files-exfiltration - obfuscation - uses-telegram-bot

Source: kam193 (39bf40d5056dc821bcedf5fcc304e26d9e6566f5beb508b6a01874b49d32becd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.