pypi

python-rootpath @0.1.9

Vulnerability report · Last retrieved from osv.dev August 15, 2026 at 1:35 PM UTC

Malicious

OSV ID

MAL-2025-191841

Ecosystem

pypi

Summary

Hidden code downloads, saves and import a remote script. The package itself is a clone of a legitimate "rootpath". At the time of analysis, the remote script did not do any harmful action --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-11-python-rootpath Reasons (based on the campaign): - Downloads and executes a remote malicious script. - clones-real-package

Source: kam193 (bb867560d676e7b79ce110b230906a9630feb223cbcb6072bff5a2636c60a3c7)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.