mlflow-otel-instrumentor @1.1.0
Vulnerability report · Last retrieved from osv.dev August 24, 2026 at 4:15 AM UTC
OSV ID
MAL-2026-14384
Ecosystem
pypi
Summary
During installation package downloads and executes an executable. The remote executable appears to be broken but suggests intentions for persistence via systemd services, cryptocurrency mining and propagating over the network. Campaign shows some similarities with 2026-08-boto4 --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-mlflow-otel-instrumentor Reasons (based on the campaign): - typosquatting - Downloads and executes a remote executable. - worm - persistence - network-scan - cryptominer
Source: kam193 (596b37cefcfec9359e87bfd5663962ce80c05c8851c4f894b6b4ea294ee0bbfd)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.