python-rootpath @0.1.9
Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 1:35 PM UTC
OSV ID
MAL-2025-191841
Ecosystem
pypi
Summary
Hidden code downloads, saves and import a remote script. The package itself is a clone of a legitimate "rootpath". At the time of analysis, the remote script did not do any harmful action --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-python-rootpath Reasons (based on the campaign): - Downloads and executes a remote malicious script. - clones-real-package
Source: kam193 (bb867560d676e7b79ce110b230906a9630feb223cbcb6072bff5a2636c60a3c7)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.