pypi

my-service-manager @1.0.7

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 1:32 PM UTC

Malicious

OSV ID

MAL-2024-12309

Ecosystem

pypi

Summary

While the package appears to be a manager for Windows service, the linked executable is an infostealer with capabilities like cookie stealing ang keylogger. The package only supports installing it --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-12-BetterMint Reasons (based on the campaign): - infostealer - exfiltration-generic - Downloads and executes a remote executable. - keylogger - exfiltration-browser-data - The package contains code to detect if it is running in a sandbox environment.

Source: kam193 (58c8e4c726cef11c6d7d60916210f532060a6ff7a98bb7fea5872eb10335dd5d)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.