neroteam-v1 @1.0.7
Vulnerability report · Last retrieved from osv.dev July 21, 2026 at 3:12 AM UTC
OSV ID
MAL-2026-10868
Ecosystem
pypi
Summary
Obfuscated code is used to abuse systems of garena[.]com for mass account generation, bypassing their security systems. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-07-neroteam-v1 Reasons (based on the campaign): - obfuscation - abusing-3rd-api - The package contains code to detect if it is running in a sandbox environment.
Source: kam193 (458a2993d1a429a687102ddfca3f9fc0c91f72373b07ccad6ff83fb56add7e58)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.