pypi

pdf2doc @0.3.9

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 3:36 PM UTC

Malicious

OSV ID

MAL-2024-11657

Ecosystem

pypi

Summary

During installation, the code attempts to exfiltrate basic data (username, host name) and send to the attacker. The package looks to be a clone of an existing one --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-09-pdf2doc Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - typosquatting - obfuscation - dependency-confusion - The package overrides the install command in setup.py to execute malicious code during installation. - clones-real-package

Source: kam193 (ae55659200290f97e3d07c41d49af574eb14ad3dc5913535e8d100cf2c48dd58)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.