pyservercheck @0.1.1
Vulnerability report · Last retrieved from osv.dev August 31, 2026 at 7:39 AM UTC
OSV ID
MAL-2026-15603
Ecosystem
pypi
Summary
Package embeds obfuscated, JS-based malware downloading further remote stages. The code is triggered during building the package and on every Python startup (via PTH file). The next-stage IP is delivered via a blockchain. The payload and embedded IoCs are consistent with campaigns attributed to Lazarus APT/PolinRider. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-08-pybitjs Reasons (based on the campaign): - obfuscation - Downloads and executes a remote malicious script. - malware - abuses-pth - c2-in-blockchain
Source: kam193 (4b365b9df06973db4f112bdbf2ad704dcc91c1b7b3eaceddb06a8e884c3f760a)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.