pybitjs @0.1.0
Vulnerability report · Last retrieved from osv.dev August 26, 2026 at 11:24 PM UTC
OSV ID
MAL-2026-14545
Ecosystem
pypi
Summary
Package embeds obfuscated, JS-based malware downloading further remote stages. The code is triggered during building the package and on every Python startup (via PTH file). The next-stage IP is delivered via a blockchain. The payload and embedded IoCs are consistent with campaigns attributed to Lazarus APT/PolinRider. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pybitjs Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - malware - abuses-pth - c2-in-blockchain
Source: kam193 (8cf3b72788a1ad482702768ea3b7f958793a0997cf77342578c31bc6dcfd23c8)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.