pdf2doc @0.3.9
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 3:36 PM UTC
OSV ID
MAL-2024-11657
Ecosystem
pypi
Summary
During installation, the code attempts to exfiltrate basic data (username, host name) and send to the attacker. The package looks to be a clone of an existing one --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2024-09-pdf2doc Reasons (based on the campaign): - The package contains code to exfiltrate basic data from the system, like IP or username. It has a limited risk. - typosquatting - obfuscation - dependency-confusion - The package overrides the install command in setup.py to execute malicious code during installation. - clones-real-package
Source: kam193 (ae55659200290f97e3d07c41d49af574eb14ad3dc5913535e8d100cf2c48dd58)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.