pypi
Malicious pdf-converter-pro @1.0.0
Vulnerability report · Last retrieved from osv.dev June 27, 2026 at 12:51 AM UTC
OSV ID
MAL-2026-6541
Ecosystem
pypi
Summary
Package hides code exfiltrating source code files if run as module. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-06-pdf-converter-pro Reasons (based on the campaign): - files-exfiltration - A Telegram webhook is used to send collected data.
Source: kam193 (5978e6d195a6e1aed1e705347db44516aca76c3a6e40ef1f47fb83087588ee16)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.