pypi

pyservercheck @0.1.1

Vulnerability report · Last retrieved from osv.dev August 31, 2026 at 7:39 AM UTC

Malicious

OSV ID

MAL-2026-15603

Ecosystem

pypi

Summary

Package embeds obfuscated, JS-based malware downloading further remote stages. The code is triggered during building the package and on every Python startup (via PTH file). The next-stage IP is delivered via a blockchain. The payload and embedded IoCs are consistent with campaigns attributed to Lazarus APT/PolinRider. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pybitjs Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - malware - abuses-pth - c2-in-blockchain

Source: kam193 (4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.